EXPOSURES › CVE-2017-15944
CVE-2017-15944
HIGH ⌖ ON CISA KEV · EXPLOITEDA Palo Alto Networks PAN-OS vulnerability allowed for chained remote code execution, actively exploited in the wild.
Multiple, unspecified vulnerabilities within Palo Alto Networks' PAN-OS platform enable remote code execution when chained, demonstrating a recurring security weakness. DIB organizations using PAN-OS must immediately assess their deployments, apply available patches, and review network segmentation to mitigate potential compromise. This highlights the need for rigorous vendor risk management and continuous monitoring.
Shame score — The recurring nature of critical vulnerabilities in a major cybersecurity vendor's flagship product reflects a significant negligence in security practices.
▸ RECOMMENDED ACTION Actively exploited (CISA KEV) — remediate now, ahead of your normal patch cycle.
Palo Alto Networks PAN-OS contains multiple, unspecified vulnerabilities which can allow for remote code execution when chained.
| PRODUCT | STATUS |
|---|---|
| GCS-HIGH Palo Alto Networks, Inc. |
Ready |
| Palo Alto Networks Government Cloud Services Palo Alto Networks, Inc. |
Authorized |