CVE-2012-6592Critical

CVE-2012-6592 Command Injection Vulnerability

Published
April 27, 2012
Last Modified
April 27, 2012

🔗 CVE IDs covered (1)

📋 Description

A vulnerability exists whereby an unauthenticated user can inject commands as root on the device. (Ref #31091) This vulnerability can result in arbitrary command execution, and can result in total compromise of the device. This issue affects PAN-OS 4.0.4 and earlier; PAN-OS 3.1.9 and earlier.

🎯 Affected products1

  • PAN-OS

✅ Remediation

PAN-OS 4.0.5 and later; PAN-OS 3.1.10 and later. Workarounds and mitigations: This issue affects the management interface of the device. Security appliance management best practices dictate that the management interface be isolated and strictly limited only to security administration personnel.

🔗 References (1)