CVE-2016-3655

The management web interface in Palo Alto Networks PAN-OS before 5.0.18, 6.0.x before 6.0.13, 6.1.x before 6.1.10, and 7.0.x before 7.0.5 allows remote attackers to execute arbitrary OS commands via an unspecified API call.
ProviderTypeBase ScoreAtk. VectorAtk. ComplexityPriv. RequiredVector
NISTPrimary
9.8 CRITICAL
NETWORK
LOW
NONE
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Base Score
CVSS 3.x
EPSS Score
Percentile: Unknown
Affected Products (NVD)
VendorProductVersion
paloaltonetworkspan-os
5.0.0 ≤
𝑥
< 5.0.18
paloaltonetworkspan-os
5.1 ≤
𝑥
< 5.1.11
paloaltonetworkspan-os
6.0.0 ≤
𝑥
< 6.0.13
paloaltonetworkspan-os
6.1.0 ≤
𝑥
< 6.1.10
paloaltonetworkspan-os
7.0.0 ≤
𝑥
≤ 7.0.5
𝑥
= Vulnerable software versions