CVE-2024-8686

EUVD-2024-49345
A command injection vulnerability in Palo Alto Networks PAN-OS software enables an authenticated administrator to bypass system restrictions and run arbitrary commands as root on the firewall.
OS Command Injection
ProviderTypeBase ScoreAtk. VectorAtk. ComplexityPriv. RequiredVector
NISTPrimary
7.2 HIGH
NETWORK
LOW
HIGH
CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H
Base Score
CVSS 3.x
EPSS Score
Percentile: 51%
Affected Products (NVD)
VendorProductVersion
paloaltonetworkspan-os
11.2.0 ≤
𝑥
≤ 11.2.2
𝑥
= Vulnerable software versions
Early Detection
Affected products identified ahead of NVD analysis through intelligence sources.
VendorProductVersionSource
paloaltonetworkspan-os
11.2.0 ≤
𝑥
< 11.2.2
ADP
paloaltonetworkscloud_ngfw
𝑥
< *
ADP
paloaltonetworksprisma_access
𝑥
< *
ADP