CVE-2017-15940: Command Injection
The web interface packet capture management component in Palo Alto Networks PAN-OS before 6.1.19, 7.0.x before 7.0.19, 7.1.x before 7.1.14, and 8.0.x before 8.0.6 allows remote authenticated users to execute arbitrary code via unspecified vectors.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2017-15940?
CVE-2017-15940 has been classified with a high severity level due to its potential to allow remote code execution.
How do I fix CVE-2017-15940?
To fix CVE-2017-15940, upgrade the Palo Alto Networks PAN-OS to versions 6.1.19, 7.0.19, 7.1.14, or 8.0.6 or later, depending on the version currently in use.
Who is affected by CVE-2017-15940?
CVE-2017-15940 affects remote authenticated users of Palo Alto Networks PAN-OS versions prior to the specified updates.
What type of vulnerability is CVE-2017-15940?
CVE-2017-15940 is a remote code execution vulnerability that can be exploited through the web interface packet capture management component.
Is there a workaround for CVE-2017-15940?
There are no specific workarounds for CVE-2017-15940; applying the necessary updates is the recommended solution to mitigate the vulnerability.