Skip to content
COOEY

EXPOSURES › CVE-2019-1579

CVE-2019-1579

CRITICAL ⌖ ON CISA KEV · EXPLOITED
DETAIL
SourceCISA-KEV · kev Published2022-01-10 Referencehttps://nvd.nist.gov/vuln/detail/CVE-2019-1579 ↗
⚡ RCE ⌖ EXPLOITED IN THE WILD SHAME 72/100 ransomwarerceexploited-in-wild

A critical, actively exploited vulnerability in Palo Alto Networks PAN-OS allows remote code execution via GlobalProtect interfaces.

PAN-OS, a widely used firewall platform, contained a remote code execution vulnerability exploitable through GlobalProtect. This poses a significant risk to DIB organizations relying on Palo Alto Networks, potentially leading to system compromise and data exfiltration; immediate patching and security assessment are crucial.

Shame score — The vulnerability's active exploitation and potential for ransomware deployment demonstrates a significant security oversight by a major vendor.

▸ RECOMMENDED ACTION  Actively exploited (CISA KEV) — remediate now, ahead of your normal patch cycle.

DESCRIPTION

Remote Code Execution in PAN-OS with GlobalProtect Portal or GlobalProtect Gateway Interface enabled.

AFFECTED FEDRAMP PRODUCTS · 2
PRODUCTSTATUS
GCS-HIGH
Palo Alto Networks, Inc.
Ready
Palo Alto Networks Government Cloud Services
Palo Alto Networks, Inc.
Authorized