CVE-2016-3655

The management web interface in Palo Alto Networks PAN-OS before 5.0.18, 6.0.x before 6.0.13, 6.1.x before 6.1.10, and 7.0.x before 7.0.5 allows remote attackers to execute arbitrary OS commands via an unspecified API call.
ProviderTypeBase ScoreAtk. VectorAtk. ComplexityPriv. RequiredVector
NISTNIST
9.8 CRITICAL
NETWORK
LOW
NONE
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
mitreCNA
---
---
CVEADP
---
---
Base Score
CVSS 3.x
EPSS Score
Percentile: 81%
VendorProductVersion
paloaltonetworkspan-os
5.0.0 ≤
𝑥
< 5.0.18
paloaltonetworkspan-os
5.1 ≤
𝑥
< 5.1.11
paloaltonetworkspan-os
6.0.0 ≤
𝑥
< 6.0.13
paloaltonetworkspan-os
6.1.0 ≤
𝑥
< 6.1.10
paloaltonetworkspan-os
7.0.0 ≤
𝑥
≤ 7.0.5
𝑥
= Vulnerable software versions