CVE-2016-3654

EUVD-2016-4679
The device management command line interface (CLI) in Palo Alto Networks PAN-OS before 5.0.18, 5.1.x before 5.1.11, 6.0.x before 6.0.13, 6.1.x before 6.1.10, and 7.0.x before 7.0.5H2 allows remote authenticated administrators to execute arbitrary OS commands via an SSH command parameter.
ProviderTypeBase ScoreAtk. VectorAtk. ComplexityPriv. RequiredVector
NISTPrimary
7.2 HIGH
NETWORK
LOW
HIGH
CVSS:3.0/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H
Base Score
CVSS 3.x
EPSS Score
Percentile: 66%
Affected Products (NVD)
VendorProductVersion
paloaltonetworkspan-os
5.0.0 ≤
𝑥
< 5.0.18
paloaltonetworkspan-os
5.1 ≤
𝑥
< 5.1.11
paloaltonetworkspan-os
6.0.0 ≤
𝑥
< 6.0.13
paloaltonetworkspan-os
6.1.0 ≤
𝑥
< 6.1.10
paloaltonetworkspan-os
7.0.0 ≤
𝑥
≤ 7.0.5
𝑥
= Vulnerable software versions