CVE-2019-1579: Palo Alto Networks PAN-OS Remote Code Execution Vulnerability
Remote Code Execution in PAN-OS 7.1.18 and earlier, PAN-OS 8.0.11-h1 and earlier, and PAN-OS 8.1.2 and earlier with GlobalProtect Portal or GlobalProtect Gateway Interface enabled may allow an unauthenticated remote attacker to execute arbitrary code.
Other sources
Remote Code Execution in PAN-OS with GlobalProtect Portal or GlobalProtect Gateway Interface enabled.
— CISA
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Configuration
Disable the GlobalProtect Portal and/or GlobalProtect Gateway Interface on affected PAN-OS devices if the feature is not required to mitigate the remote code execution risk.
PAN-OS GlobalProtect Portal / GlobalProtect Gateway Interface enabled = false
Event History
Frequently Asked Questions
What is CVE-2019-1579?
CVE-2019-1579 is a Palo Alto Networks PAN-OS Remote Code Execution Vulnerability.
How severe is CVE-2019-1579?
CVE-2019-1579 has a severity rating of 8.1, which is considered high.
Which software versions are affected by CVE-2019-1579?
PAN-OS 7.1.18 and earlier, PAN-OS 8.0.11-h1 and earlier, and PAN-OS 8.1.2 and earlier with GlobalProtect Portal or GlobalProtect Gateway Interface enabled are affected.
How can an attacker exploit CVE-2019-1579?
An unauthenticated remote attacker can exploit CVE-2019-1579 to execute arbitrary code.
Where can I find more information about CVE-2019-1579?
You can find more information about CVE-2019-1579 at the following references: [SecurityFocus](http://www.securityfocus.com/bid/109310), [Devco.re Blog](https://devco.re/blog/2019/07/17/attacking-ssl-vpn-part-1-PreAuth-RCE-on-Palo-Alto-GlobalProtect-with-Uber-as-case-study/), [SonicWall PSIRT](https://psirt.global.sonicwall.com/vuln-detail/SNWLID-2019-0010).