Home ▼ Bookkeeping
Online ▼ Security
Audits ▼
Managed
DNS ▼
About
Order
FAQ
Acceptable Use Policy
Dynamic DNS Clients
Configure Domains Dyanmic DNS Update Password Network
Monitor ▼
Enterprise Package
Advanced Package
Standard Package
Free Trial
FAQ
Price/Feature Summary
Order/Renew
Examples
Configure/Status Alert Profiles | |||
Test ID: | 1.3.6.1.4.1.25623.1.0.140074 |
Category: | Palo Alto PAN-OS Local Security Checks |
Title: | Palo Alto PAN-OS Local Privilege Escalation (PAN-SA-2016-0034) |
Summary: | Palo Alto Networks firewalls do not properly validate certain environment variables which can potentially allow executing code with higher privileges. A potential attacker with local shell access could manipulate arbitrary environment variables which could result in a process running with higher privileges. |
Description: | Summary: Palo Alto Networks firewalls do not properly validate certain environment variables which can potentially allow executing code with higher privileges. A potential attacker with local shell access could manipulate arbitrary environment variables which could result in a process running with higher privileges. Affected Software/OS: PAN-OS 5.0.19 and earlier, PAN-OS 5.1.12 and earlier, PAN-OS 6.0.14 and earlier, PAN-OS 6.1.14 and earlier, PAN-OS 7.0.10 and earlier, PAN-OS 7.1.5 and earlier Solution: Update to PAN-OS 5.0.20 and later, PAN-OS 5.1.13 and later, PAN-OS 6.0.15 and later, PAN-OS 6.1.15 and later, PAN-OS 7.0.11 and later, PAN-OS 7.1.6 and later CVSS Score: 4.6 CVSS Vector: AV:L/AC:L/Au:N/C:P/I:P/A:P |
Cross-Ref: |
Common Vulnerability Exposure (CVE) ID: CVE-2016-9151 BugTraq ID: 94400 http://www.securityfocus.com/bid/94400 https://www.exploit-db.com/exploits/40788/ https://www.exploit-db.com/exploits/40789/ http://www.securitytracker.com/id/1037381 |
Copyright | Copyright (C) 2016 Greenbone Networks GmbH |
This is only one of 99761 vulnerability tests in our test suite. Find out more about running a complete security audit. To run a free test of this vulnerability against your system, register below. |