CVE-2023-6795

An OS command injection vulnerability in Palo Alto Networks PAN-OS software enables an authenticated administrator to disrupt system processes and potentially execute arbitrary code with limited privileges on the firewall.
OS Command Injection
ProviderTypeBase ScoreAtk. VectorAtk. ComplexityPriv. RequiredVector
NISTNIST
5.5 MEDIUM
NETWORK
LOW
HIGH
CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:L/A:N
palo_altoCNA
5.5 MEDIUM
NETWORK
LOW
HIGH
CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:L/A:N
CVEADP
---
---
Base Score
CVSS 3.x
EPSS Score
Percentile: 31%
VendorProductVersion
paloaltonetworkspan-os
8.1.0 ≤
𝑥
< 8.1.24
paloaltonetworkspan-os
9.0.0 ≤
𝑥
< 9.0.17
paloaltonetworkspan-os
9.1.0 ≤
𝑥
< 9.1.12
paloaltonetworkspan-os
10.0.0 ≤
𝑥
< 10.0.9
paloaltonetworkspan-os
10.1.0 ≤
𝑥
< 10.1.3
𝑥
= Vulnerable software versions