CVE-2012-6601: OS Command Injection
The device-management command-line interface in Palo Alto Networks PAN-OS before 3.1.12, 4.0.x before 4.0.10, and 4.1.x before 4.1.4 allows remote attackers to execute arbitrary code via unspecified vectors, aka Ref ID 36983.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2012-6601?
CVE-2012-6601 is considered a critical vulnerability as it allows remote attackers to execute arbitrary code on affected systems.
How do I fix CVE-2012-6601?
To resolve CVE-2012-6601, upgrade your Palo Alto Networks PAN-OS to versions 3.1.12, 4.0.10, or 4.1.4 or later.
Which versions of PAN-OS are affected by CVE-2012-6601?
CVE-2012-6601 affects PAN-OS versions prior to 3.1.12, 4.0.x versions before 4.0.10, and 4.1.x versions prior to 4.1.4.
Can CVE-2012-6601 be exploited remotely?
Yes, CVE-2012-6601 can be exploited by remote attackers to execute arbitrary code without authentication.
What is the attack vector for CVE-2012-6601?
The exact attack vector for CVE-2012-6601 has not been publicly disclosed, but it enables arbitrary code execution through unspecified methods.