Palo Alto Networks PAN-OS Remote Code Execution Vulnerability
cve CVE-2017-15944 3 sources, 4 claims · Watch
CISA Known Exploited Vulnerabilities writes:
Palo Alto Networks PAN-OS Remote Code Execution Vulnerability Palo Alto Networks PAN-OS contains multiple, unspecified vulnerabilities which can allow for remote code execution when chained. Apply updates per vendor instructions. https://security.paloaltonetworks.com/CVE-2017-15944; https://nvd.nist.gov/vuln/detail/CVE-2017-15944 the claim
Palo Alto Networks PAN-OS Remote Code Execution Vulnerability Palo Alto Networks PAN-OS contains multiple, unspecified vulnerabilities which can allow for remote code execution when chained. Apply updates per vendor instructions. https://security.paloaltonetworks.com/CVE-2017-15944; https://nvd.nist.gov/vuln/detail/CVE-2017-15944 the claim
What each source says
| Property | Source | Said | Means here |
|---|---|---|---|
| Author author | Exploit-DB | Metasploitreceipt
What the source handed over{
"aliases": "",
"application_url": "",
"author": "Metasploit",
"codes": "CVE-2017-15944",
"date_added": "2018-05-08",
"date_published": "2018-05-08",
"date_updated": "2018-05-09",
"description": "Palo Alto Networks - 'readSessionVarsFromFile()' Session Corruption (Metasploit)",
"file": "exploits/unix/remote/44597.rb",
"id": "44597",
"platform": "unix",
"port": "443",
"screenshot_url": "",
"source_url": "https://raw.githubusercontent.com/rapid7/metasploit-framework/0240c3f010785192c131ec9a7bcc5fd167e2eb77/modules/exploits/linux/http/panos_readsessionvars.rb",
"tags": "Metasploit Framework (MSF)",
"type": "remote",
"verified": "1"
} | — |
| Author author | Philip Petterssonreceipt
What the source handed over{
"aliases": "",
"application_url": "",
"author": "Philip Pettersson",
"codes": "CVE-2017-15944",
"date_added": "2017-12-14",
"date_published": "2017-12-14",
"date_updated": "2018-05-08",
"description": "Palo Alto Networks Firewalls - Root Remote Code Execution",
"file": "exploits/hardware/remote/43342.txt",
"id": "43342",
"platform": "hardware",
"port": "",
"screenshot_url": "",
"source_url": "http://seclists.org/fulldisclosure/2017/Dec/38",
"tags": "",
"type": "remote",
"verified": "1"
} | — | |
| Due date due_date | CISA Known Exploited Vulnerabilities | 2022-09-08receipt
What the source handed over{
"cveID": "CVE-2017-15944",
"cwes": "",
"dateAdded": "2022-08-18",
"dueDate": "2022-09-08",
"forensicTriage": "No",
"knownRansomwareCampaignUse": "Unknown",
"notes": "https://security.paloaltonetworks.com/CVE-2017-15944; https://nvd.nist.gov/vuln/detail/CVE-2017-15944",
"product": "PAN-OS",
"requiredAction": "Apply updates per vendor instructions.",
"shortDescription": "Palo Alto Networks PAN-OS contains multiple, unspecified vulnerabilities which can allow for remote code execution when chained.",
"vendorProject": "Palo Alto Networks",
"vulnerabilityName": "Palo Alto Networks PAN-OS Remote Code Execution Vulnerability"
} | — |
| Exploited exploited | CISA Known Exploited Vulnerabilities | yesreceipt
What the source handed over{
"cveID": "CVE-2017-15944",
"cwes": "",
"dateAdded": "2022-08-18",
"dueDate": "2022-09-08",
"forensicTriage": "No",
"knownRansomwareCampaignUse": "Unknown",
"notes": "https://security.paloaltonetworks.com/CVE-2017-15944; https://nvd.nist.gov/vuln/detail/CVE-2017-15944",
"product": "PAN-OS",
"requiredAction": "Apply updates per vendor instructions.",
"shortDescription": "Palo Alto Networks PAN-OS contains multiple, unspecified vulnerabilities which can allow for remote code execution when chained.",
"vendorProject": "Palo Alto Networks",
"vulnerabilityName": "Palo Alto Networks PAN-OS Remote Code Execution Vulnerability"
} | — |
| Forensic triage forensic_triage | CISA Known Exploited Vulnerabilities | falsereceipt
What the source handed over{
"cveID": "CVE-2017-15944",
"cwes": "",
"dateAdded": "2022-08-18",
"dueDate": "2022-09-08",
"forensicTriage": "No",
"knownRansomwareCampaignUse": "Unknown",
"notes": "https://security.paloaltonetworks.com/CVE-2017-15944; https://nvd.nist.gov/vuln/detail/CVE-2017-15944",
"product": "PAN-OS",
"requiredAction": "Apply updates per vendor instructions.",
"shortDescription": "Palo Alto Networks PAN-OS contains multiple, unspecified vulnerabilities which can allow for remote code execution when chained.",
"vendorProject": "Palo Alto Networks",
"vulnerabilityName": "Palo Alto Networks PAN-OS Remote Code Execution Vulnerability"
} | — |
| Known ransomware campaign use known_ransomware_campaign_use | CISA Known Exploited Vulnerabilities | Unknownreceipt
What the source handed over{
"cveID": "CVE-2017-15944",
"cwes": "",
"dateAdded": "2022-08-18",
"dueDate": "2022-09-08",
"forensicTriage": "No",
"knownRansomwareCampaignUse": "Unknown",
"notes": "https://security.paloaltonetworks.com/CVE-2017-15944; https://nvd.nist.gov/vuln/detail/CVE-2017-15944",
"product": "PAN-OS",
"requiredAction": "Apply updates per vendor instructions.",
"shortDescription": "Palo Alto Networks PAN-OS contains multiple, unspecified vulnerabilities which can allow for remote code execution when chained.",
"vendorProject": "Palo Alto Networks",
"vulnerabilityName": "Palo Alto Networks PAN-OS Remote Code Execution Vulnerability"
} | — |
| Platform platform not compared | Exploit-DB | hardwarereceipt
What the source handed over{
"aliases": "",
"application_url": "",
"author": "Philip Pettersson",
"codes": "CVE-2017-15944",
"date_added": "2017-12-14",
"date_published": "2017-12-14",
"date_updated": "2018-05-08",
"description": "Palo Alto Networks Firewalls - Root Remote Code Execution",
"file": "exploits/hardware/remote/43342.txt",
"id": "43342",
"platform": "hardware",
"port": "",
"screenshot_url": "",
"source_url": "http://seclists.org/fulldisclosure/2017/Dec/38",
"tags": "",
"type": "remote",
"verified": "1"
} | — |
| Platform platform not compared | unixreceipt
What the source handed over{
"aliases": "",
"application_url": "",
"author": "Metasploit",
"codes": "CVE-2017-15944",
"date_added": "2018-05-08",
"date_published": "2018-05-08",
"date_updated": "2018-05-09",
"description": "Palo Alto Networks - 'readSessionVarsFromFile()' Session Corruption (Metasploit)",
"file": "exploits/unix/remote/44597.rb",
"id": "44597",
"platform": "unix",
"port": "443",
"screenshot_url": "",
"source_url": "https://raw.githubusercontent.com/rapid7/metasploit-framework/0240c3f010785192c131ec9a7bcc5fd167e2eb77/modules/exploits/linux/http/panos_readsessionvars.rb",
"tags": "Metasploit Framework (MSF)",
"type": "remote",
"verified": "1"
} | — | |
| Platform platform not compared | Metasploit exploit modules | Unixreceipt
What the source handed over{
"aliases": [],
"arch": "cmd",
"author": [
"Philip Pettersson <philip.pettersson@gmail com>",
"hdm <x@hdm.io>"
],
"autofilter_ports": [
80,
8080,
443,
8000,
8888,
8880,
8008,
3000,
8443
],
"autofilter_services": [
"http",
"https"
],
"check": false,
"default_credential": false,
"description": "This module exploits a chain of vulnerabilities in Palo Alto Networks products running\n PAN-OS versions prior to 6.1.19, 7.0.19, 7.1.14, and 8.0.6. This chain starts by using\n an authentication bypass flaw to to exploit an XML injection issue, which is then\n abused to create an arbitrary directory, and finally gains root code execution by\n exploiting a vulnerable cron script. This module uses an initial reverse TLS callback\n to stage arbitrary payloads on the target appliance. The cron job used for the final\n payload runs every 15 minutes by default and exploitation can take up to 20 minutes.",
"disclosure_date": "2017-12-11",
"fullname": "exploit/linux/http/panos_readsessionvars",
"is_install_path": true,
"mod_time": "2025-06-23 12:43:46 +0000",
"name": "Palo Alto Networks readSessionVarsFromFile() Session Corruption",
"needs_cleanup": true,
"notes": {
"Reliability": [
"unknown-reliability"
],
"SideEffects": [
"unknown-side-effects"
],
"Stability": [
"unknown-stability"
]
},
"path": "/modules/exploits/linux/http/panos_readsessionvars.rb",
"platform": "Unix",
"post_auth": false,
"rank": 600,
"ref_name": "linux/http/panos_readsessionvars",
"references": [
"CVE-2017-15944",
"URL-https://seclists.org/fulldisclosure/2017/Dec/38",
"BID-102079"
],
"rport": 443,
"session_types": false,
"targets": [
"Automatic"
],
"type": "exploit"
} | — |
| Product product | CISA Known Exploited Vulnerabilities | PAN-OSreceipt
What the source handed over{
"cveID": "CVE-2017-15944",
"cwes": "",
"dateAdded": "2022-08-18",
"dueDate": "2022-09-08",
"forensicTriage": "No",
"knownRansomwareCampaignUse": "Unknown",
"notes": "https://security.paloaltonetworks.com/CVE-2017-15944; https://nvd.nist.gov/vuln/detail/CVE-2017-15944",
"product": "PAN-OS",
"requiredAction": "Apply updates per vendor instructions.",
"shortDescription": "Palo Alto Networks PAN-OS contains multiple, unspecified vulnerabilities which can allow for remote code execution when chained.",
"vendorProject": "Palo Alto Networks",
"vulnerabilityName": "Palo Alto Networks PAN-OS Remote Code Execution Vulnerability"
} | — |
| Rank rank | Metasploit exploit modules | 600 Excellent. Cannot crash the service. A memory-corruption exploit does not qualify. receipt
What the source handed over{
"aliases": [],
"arch": "cmd",
"author": [
"Philip Pettersson <philip.pettersson@gmail com>",
"hdm <x@hdm.io>"
],
"autofilter_ports": [
80,
8080,
443,
8000,
8888,
8880,
8008,
3000,
8443
],
"autofilter_services": [
"http",
"https"
],
"check": false,
"default_credential": false,
"description": "This module exploits a chain of vulnerabilities in Palo Alto Networks products running\n PAN-OS versions prior to 6.1.19, 7.0.19, 7.1.14, and 8.0.6. This chain starts by using\n an authentication bypass flaw to to exploit an XML injection issue, which is then\n abused to create an arbitrary directory, and finally gains root code execution by\n exploiting a vulnerable cron script. This module uses an initial reverse TLS callback\n to stage arbitrary payloads on the target appliance. The cron job used for the final\n payload runs every 15 minutes by default and exploitation can take up to 20 minutes.",
"disclosure_date": "2017-12-11",
"fullname": "exploit/linux/http/panos_readsessionvars",
"is_install_path": true,
"mod_time": "2025-06-23 12:43:46 +0000",
"name": "Palo Alto Networks readSessionVarsFromFile() Session Corruption",
"needs_cleanup": true,
"notes": {
"Reliability": [
"unknown-reliability"
],
"SideEffects": [
"unknown-side-effects"
],
"Stability": [
"unknown-stability"
]
},
"path": "/modules/exploits/linux/http/panos_readsessionvars.rb",
"platform": "Unix",
"post_auth": false,
"rank": 600,
"ref_name": "linux/http/panos_readsessionvars",
"references": [
"CVE-2017-15944",
"URL-https://seclists.org/fulldisclosure/2017/Dec/38",
"BID-102079"
],
"rport": 443,
"session_types": false,
"targets": [
"Automatic"
],
"type": "exploit"
} | — |
| Type type | Exploit-DB | remotereceipt
What the source handed over{
"aliases": "",
"application_url": "",
"author": "Philip Pettersson",
"codes": "CVE-2017-15944",
"date_added": "2017-12-14",
"date_published": "2017-12-14",
"date_updated": "2018-05-08",
"description": "Palo Alto Networks Firewalls - Root Remote Code Execution",
"file": "exploits/hardware/remote/43342.txt",
"id": "43342",
"platform": "hardware",
"port": "",
"screenshot_url": "",
"source_url": "http://seclists.org/fulldisclosure/2017/Dec/38",
"tags": "",
"type": "remote",
"verified": "1"
} | — |
| Vendor project vendor_project | CISA Known Exploited Vulnerabilities | Palo Alto Networksreceipt
What the source handed over{
"cveID": "CVE-2017-15944",
"cwes": "",
"dateAdded": "2022-08-18",
"dueDate": "2022-09-08",
"forensicTriage": "No",
"knownRansomwareCampaignUse": "Unknown",
"notes": "https://security.paloaltonetworks.com/CVE-2017-15944; https://nvd.nist.gov/vuln/detail/CVE-2017-15944",
"product": "PAN-OS",
"requiredAction": "Apply updates per vendor instructions.",
"shortDescription": "Palo Alto Networks PAN-OS contains multiple, unspecified vulnerabilities which can allow for remote code execution when chained.",
"vendorProject": "Palo Alto Networks",
"vulnerabilityName": "Palo Alto Networks PAN-OS Remote Code Execution Vulnerability"
} | — |
| Verified verified | Exploit-DB | truereceipt
What the source handed over{
"aliases": "",
"application_url": "",
"author": "Philip Pettersson",
"codes": "CVE-2017-15944",
"date_added": "2017-12-14",
"date_published": "2017-12-14",
"date_updated": "2018-05-08",
"description": "Palo Alto Networks Firewalls - Root Remote Code Execution",
"file": "exploits/hardware/remote/43342.txt",
"id": "43342",
"platform": "hardware",
"port": "",
"screenshot_url": "",
"source_url": "http://seclists.org/fulldisclosure/2017/Dec/38",
"tags": "",
"type": "remote",
"verified": "1"
} | — |
vulnerability
| Palo Alto Networks PAN-OS Remote Code Execution Vulnerability zetlyn/cve-kev · 2022-08-18 | due_date 2022-09-08 exploited yes forensic_triage false known_ransomware_campaign_use Unknown product PAN-OS vendor_project Palo Alto Networks |
exploit
| Palo Alto Networks readSessionVarsFromFile() Session Corruption zetlyn/cve-metasploit · 2017-12-11 | platform Unix rank 600 | source |
| Palo Alto Networks Firewalls - Root Remote Code Execution zetlyn/cve-exploitdb · 2017-12-14 | author Philip Pettersson platform hardware type remote verified true | source |
| Palo Alto Networks - 'readSessionVarsFromFile()' Session Corruption (Metasploit) zetlyn/cve-exploitdb · 2018-05-08 | author Metasploit platform unix type remote verified true | source |