EXPOSURES › CVE-2019-1579
CVE-2019-1579
CRITICAL ⌖ ON CISA KEV · EXPLOITEDA critical, actively exploited vulnerability in Palo Alto Networks PAN-OS allows remote code execution via GlobalProtect interfaces.
PAN-OS, a widely used firewall platform, contained a remote code execution vulnerability exploitable through GlobalProtect. This poses a significant risk to DIB organizations relying on Palo Alto Networks, potentially leading to system compromise and data exfiltration; immediate patching and security assessment are crucial.
Shame score — The vulnerability's active exploitation and potential for ransomware deployment demonstrates a significant security oversight by a major vendor.
▸ RECOMMENDED ACTION Actively exploited (CISA KEV) — remediate now, ahead of your normal patch cycle.
Remote Code Execution in PAN-OS with GlobalProtect Portal or GlobalProtect Gateway Interface enabled.
| PRODUCT | STATUS |
|---|---|
| GCS-HIGH Palo Alto Networks, Inc. |
Ready |
| Palo Alto Networks Government Cloud Services Palo Alto Networks, Inc. |
Authorized |