CVE-2012-6599High
CVE-2012-6599 Command Injection Vulnerability
🔗 CVE IDs covered (1)
📋 Description
A vulnerability exists whereby an authenticated user can inject arbitrary shell commands using the device management command line interface. (Ref #33476) This vulnerability can result in arbitrary command execution, and can result in total compromise of the device. This issue affects PAN-OS 4.1.0 and earlier; PAN-OS 4.0.7 and earlier; PAN-OS 3.0.x is not affected.
🎯 Affected products1
- PAN-OS
✅ Remediation
PAN-OS 4.1.1 and later; PAN-OS 4.0.8 and later. Workarounds and mitigations: This issue affects the management interface of the device. Security appliance management best practices dictate that the management interface be isolated and strictly limited only to security administration personnel.