PAN-SA-2016-0015MediumDisclosed before NVD

PAN-SA-2016-0015 Cron local privilege escalation

Published
July 14, 2016
Last Modified
July 14, 2016

📋 Description

Palo Alto Networks firewalls use the cron infrastructure to perform household system cleanup at regular intervals. Due to an error in user input normalization, a file locally created by an end user and placed in a specific directory could be executed in a higher privilege context (Ref. 93612). Because no shell access is available to end-users, exploitation of this issue is unlikely. This issue affects PAN-OS 5.0.18 and prior; PAN-OS 5.1.11 and prior; PAN-OS 6.0.13 and prior; PAN-OS 6.1.11 and prior; PAN-OS 7.0.6 and prior; PAN-OS 7.1.1 and prior

🎯 Affected products1

  • PAN-OS

✅ Remediation

PAN-OS 5.0.19 and later; PAN-OS 5.1.12 and later; PAN-OS 6.0.14 and later; PAN-OS 6.1.12 and later; PAN-OS 7.0.7 and later; PAN-OS 7.1.2 and later Workarounds and mitigations: N/A

🔗 References (1)