Skip to content
COOEY

EXPOSURES › CVE-2017-15944

CVE-2017-15944

HIGH ⌖ ON CISA KEV · EXPLOITED
DETAIL
SourceCISA-KEV · kev Published2022-08-18 Referencehttps://nvd.nist.gov/vuln/detail/CVE-2017-15944 ↗
⚡ RCE ⌖ EXPLOITED IN THE WILD SHAME 72/100 rceexploited-in-wildunpatched

A Palo Alto Networks PAN-OS vulnerability allowed for chained remote code execution, actively exploited in the wild.

Multiple, unspecified vulnerabilities within Palo Alto Networks' PAN-OS platform enable remote code execution when chained, demonstrating a recurring security weakness. DIB organizations using PAN-OS must immediately assess their deployments, apply available patches, and review network segmentation to mitigate potential compromise. This highlights the need for rigorous vendor risk management and continuous monitoring.

Shame score — The recurring nature of critical vulnerabilities in a major cybersecurity vendor's flagship product reflects a significant negligence in security practices.

▸ RECOMMENDED ACTION  Actively exploited (CISA KEV) — remediate now, ahead of your normal patch cycle.

DESCRIPTION

Palo Alto Networks PAN-OS contains multiple, unspecified vulnerabilities which can allow for remote code execution when chained.

AFFECTED FEDRAMP PRODUCTS · 2
PRODUCTSTATUS
GCS-HIGH
Palo Alto Networks, Inc.
Ready
Palo Alto Networks Government Cloud Services
Palo Alto Networks, Inc.
Authorized