Palo Alto Networks PAN-OS OpenConfig Plugin
cpe:2.3:o:paloaltonetworks:pan-os:*:*:*:*:*:*:*
- < 2.1.2
A command injection vulnerability exists in the Palo Alto Networks PAN-OS OpenConfig plugin, allowing authenticated administrators to bypass system restrictions and execute arbitrary commands via gNMI requests to the PAN-OS management web interface. The executed commands are run as the '__openconfig' user, who holds the Device Administrator role on the firewall. This vulnerability affects OpenConfig plugin versions prior to 2.1.2, with the risk being highest when the management interface is accessible from external IP addresses on the internet.
Exploitation of this vulnerability allows for command injection, with executed commands running as a privileged user on the firewall.
To address this vulnerability, update the OpenConfig plugin to version 2.1.2 or later. If the OpenConfig plugin is not in use, it can be disabled or uninstalled. For detailed instructions on managing the OpenConfig plugin, refer to the Palo Alto Networks official documentation.
Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.