CVE-2017-15944
Palo Alto Networks PAN-OS: Remote Code Execution
As of , CVE-2017-15944 in Palo Alto Networks PAN-OS is on CISA's list of exploited vulnerabilities: CISA listed it on . Our patch-first group: Patch this week.
- Exploited
- Yes: CISA listed it on 18 August 2022
- US federal deadline
- 8 September 202221 days after CISA listed it. US federal civilian agencies must fix it by then.
- Used in ransomware campaigns
- Not known to CISA
- EPSS score
- 0.98Higher than 99% of the CVEs EPSS scores. EPSS estimates the chance of exploitation activity in the next 30 days.
- EPSS when listed
- 0.95 on 18 August 2022EPSS on the day CISA listed it.
- Public exploit
- 1 Metasploit module and 2 Exploit-DB entries (2 verified)
- Fix
- Vendor advice: security.paloaltonetworks.comLinks below, from CISA's entry.
What CISA says to do
Apply updates per vendor instructions.
CISA's required action
What the flaw is
Palo Alto Networks PAN-OS contains multiple, unspecified vulnerabilities which can allow for remote code execution when chained.
CISA's description
Palo Alto Networks PAN-OS before 6.1.19, 7.0.x before 7.0.19, 7.1.x before 7.1.14, and 8.0.x before 8.0.6 allows remote attackers to execute arbitrary code via vectors involving the management interface.
The CVE record's description, from mitre
- CVE published
- 11 December 2017
- Assigned by
- mitre
- CVSS
- 9.8 Critical (CVSS 3.1, from CISA-ADP)
- CWE-20
- Improper Input Validation
- CWE-119
- Improper Restriction of Operations within the Bounds of a Memory Buffer
- CISA SSVC, exploitation
- active
- CISA SSVC, automatable
- yes
- CISA SSVC, technical impact
- total
Timeline
- The CVE record was published.
- Exploit-DB published an exploit (EDB-ID 43342).
- Exploit-DB published an exploit (EDB-ID 44597).
- CISA added it to its list of exploited vulnerabilities.
- The US federal deadline to fix it.
Public exploits
Facts from Metasploit's module list and Exploit-DB's index; we never copy exploit code.
- Metasploit: Palo Alto Networks readSessionVarsFromFile() Session Corruptionexploit module, rank excellent
- Exploit-DB: Palo Alto Networks - 'readSessionVarsFromFile()' Session Corruption (Metasploit)EDB-ID 44597, verified by Exploit-DB, 8 May 2018
- Exploit-DB: Palo Alto Networks Firewalls - Root Remote Code ExecutionEDB-ID 43342, verified by Exploit-DB, 14 December 2017
PAN-OS: other exploited entries
| Vulnerability | Product | Our group | Listed | Deadline | EPSS |
|---|---|---|---|---|---|
| CVE-2026-0257Authentication Bypass | Palo Alto Networks PAN-OS | Patch nowRansomware use, listed within a year | 0.97 | ||
| CVE-2024-0012Management Interface Authentication Bypass | Palo Alto Networks PAN-OS | Patch this weekRansomware use; Metasploit module; EPSS 0.99 | 0.99 | ||
| CVE-2024-9474Management Interface OS Command Injection | Palo Alto Networks PAN-OS | Patch this weekRansomware use; Metasploit module; EPSS 0.95 | 0.95 | ||
| CVE-2024-3400Command Injection | Palo Alto Networks PAN-OS | Patch this weekRansomware use; Metasploit module; EPSS 0.99 | 0.99 | ||
| CVE-2025-0108Authentication Bypass | Palo Alto Networks PAN-OS | Patch this weekEPSS 0.98 | 0.98 | ||
| CVE-2019-1579Remote Code Execution | Palo Alto Networks PAN-OS | Patch this weekRansomware use | 0.46 | ||
| CVE-2020-2021Authentication Bypass | Palo Alto Networks PAN-OS | Patch this weekRansomware use | 0.04 | ||
| CVE-2026-0300Out-of-bounds Write | Palo Alto Networks PAN-OS | Patch soon | 0.32 | ||
| CVE-2024-3393Malicious DNS Packet | Palo Alto Networks PAN-OS | Patch soon | 0.29 | ||
| CVE-2022-0028Reflected Amplification Denial-of-Service | Palo Alto Networks PAN-OS | Patch soon | 0.03 |
Read further
- CVE recordcve.org
- NVD entrynvd.nist.gov
- CISA's catalogcisa.gov
- EPSS for this CVEapi.first.org