CVE-2017-15944

Palo Alto Networks PAN-OS: Remote Code Execution

As of , CVE-2017-15944 in Palo Alto Networks PAN-OS is on CISA's list of exploited vulnerabilities: CISA listed it on . Our patch-first group: Patch this week.

Exploited
Yes: CISA listed it on 18 August 2022
US federal deadline
8 September 202221 days after CISA listed it. US federal civilian agencies must fix it by then.
Used in ransomware campaigns
Not known to CISA
EPSS score
0.98Higher than 99% of the CVEs EPSS scores. EPSS estimates the chance of exploitation activity in the next 30 days.
EPSS when listed
0.95 on 18 August 2022EPSS on the day CISA listed it.
Public exploit
1 Metasploit module and 2 Exploit-DB entries (2 verified)
Fix
Vendor advice: security.paloaltonetworks.comLinks below, from CISA's entry.

What CISA says to do

Apply updates per vendor instructions.

CISA's required action

What the flaw is

Palo Alto Networks PAN-OS contains multiple, unspecified vulnerabilities which can allow for remote code execution when chained.

CISA's description

Palo Alto Networks PAN-OS before 6.1.19, 7.0.x before 7.0.19, 7.1.x before 7.1.14, and 8.0.x before 8.0.6 allows remote attackers to execute arbitrary code via vectors involving the management interface.

The CVE record's description, from mitre

CVE published
11 December 2017
Assigned by
mitre
CVSS
9.8 Critical (CVSS 3.1, from CISA-ADP)
CWE-20
Improper Input Validation
CWE-119
Improper Restriction of Operations within the Bounds of a Memory Buffer
CISA SSVC, exploitation
active
CISA SSVC, automatable
yes
CISA SSVC, technical impact
total

Timeline

  1. The CVE record was published.
  2. Exploit-DB published an exploit (EDB-ID 43342).
  3. Exploit-DB published an exploit (EDB-ID 44597).
  4. CISA added it to its list of exploited vulnerabilities.
  5. The US federal deadline to fix it.

Public exploits

Facts from Metasploit's module list and Exploit-DB's index; we never copy exploit code.

PAN-OS: other exploited entries

VulnerabilityProductOur groupListedDeadlineEPSS
CVE-2026-0257Authentication BypassPalo Alto Networks PAN-OSPatch nowRansomware use, listed within a year0.97
CVE-2024-0012Management Interface Authentication BypassPalo Alto Networks PAN-OSPatch this weekRansomware use; Metasploit module; EPSS 0.990.99
CVE-2024-9474Management Interface OS Command InjectionPalo Alto Networks PAN-OSPatch this weekRansomware use; Metasploit module; EPSS 0.950.95
CVE-2024-3400Command InjectionPalo Alto Networks PAN-OSPatch this weekRansomware use; Metasploit module; EPSS 0.990.99
CVE-2025-0108Authentication BypassPalo Alto Networks PAN-OSPatch this weekEPSS 0.980.98
CVE-2019-1579Remote Code ExecutionPalo Alto Networks PAN-OSPatch this weekRansomware use0.46
CVE-2020-2021Authentication BypassPalo Alto Networks PAN-OSPatch this weekRansomware use0.04
CVE-2026-0300Out-of-bounds WritePalo Alto Networks PAN-OSPatch soon0.32
CVE-2024-3393Malicious DNS PacketPalo Alto Networks PAN-OSPatch soon0.29
CVE-2022-0028Reflected Amplification Denial-of-ServicePalo Alto Networks PAN-OSPatch soon0.03

All 12 entries for PAN-OS

Read further