CVE-2021-3045: PAN-OS: OS Command Argument Injection in Web Interface
An OS command argument injection vulnerability in the Palo Alto Networks PAN-OS web interface enables an authenticated administrator to read any arbitrary file from the file system. This issue impacts: PAN-OS 8.1 versions earlier than PAN-OS 8.1.19; PAN-OS 9.0 versions earlier than PAN-OS 9.0.14; PAN-OS 9.1 versions earlier than PAN-OS 9.1.10. PAN-OS 10.0 and later versions are not impacted.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
Palo Alto Networks PAN-OSto a version that resolves this vulnerability.Fixed in 8.1.19 - Upgrade
Upgrade
Palo Alto Networks PAN-OSto a version that resolves this vulnerability.Fixed in 9.0.14 - Upgrade
Upgrade
Palo Alto Networks PAN-OSto a version that resolves this vulnerability.Fixed in 9.1.10
Event History
Frequently Asked Questions
What is the vulnerability ID for this issue?
The vulnerability ID for this issue is CVE-2021-3045.
What is the title of this vulnerability?
The title of this vulnerability is 'An OS command argument injection vulnerability in the Palo Alto Networks PAN-OS web interface enable…'
What is the severity of CVE-2021-3045?
The severity of CVE-2021-3045 is medium.
Which versions of PAN-OS are affected by this vulnerability?
This vulnerability affects PAN-OS 8.1 versions earlier than PAN-OS 8.1.19, PAN-OS 9.0 versions earlier than PAN-OS 9.0.14, and PAN-OS 9.1 versions earlier than PAN-OS 9.1.10.
How can an authenticated administrator exploit this vulnerability?
An authenticated administrator can exploit this vulnerability to read any arbitrary file from the file system.