← Vulnerability feed

Vulnerability record · CVE-2017-15944 · published 11 December 2017

CVE-2017-15944: PAN-OS management interface input validation flaw allows remote code execution

Paloaltonetworks · Pan Os

PAN-OS versions before 6.1.19, 7.0.x before 7.0.19, 7.1.x before 7.1.14, and 8.0.x before 8.0.6 contain an input validation and memory buffer overflow flaw reachable through the management interface. A remote, unauthenticated attacker can execute arbitrary code, making this a critical exposure for any internet-facing management plane.

9.8 CVSS 3.1 Critical CISA KEV since 18 Aug 2022 EPSS 98% · top 0.1% CWE-20 · Improper input validation
9.8CVSS 3.1 base score, v2 7.5
98%EPSS exploitation probability, 30 days
YesIn CISA KEV, fix deadline passed
1Affected product versions listed by NVD
11References, 4 tagged exploit
17 Jun 2026Last modified by NVD

Description

Palo Alto Networks PAN-OS before 6.1.19, 7.0.x before 7.0.19, 7.1.x before 7.1.14, and 8.0.x before 8.0.6 allows remote attackers to execute arbitrary code via vectors involving the management interface.

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Automated analysis

Generated by VULONE's analysis model from the NVD record, CISA KEV and EPSS data on 16 September 2026. Confidence: high.

critical priorityUnauthenticated remote code execution on a perimeter security device, listed in CISA KEV with public exploits and near-maximum EPSS.

What it is

PAN-OS versions before 6.1.19, 7.0.x before 7.0.19, 7.1.x before 7.1.14, and 8.0.x before 8.0.6 contain an input validation and memory buffer overflow flaw reachable through the management interface. A remote, unauthenticated attacker can execute arbitrary code, making this a critical exposure for any internet-facing management plane.

Impact

Successful exploitation gives the attacker arbitrary code execution on the firewall or management appliance, with high impact to confidentiality, integrity and availability. That level of control over a perimeter device can enable traffic manipulation, credential theft and lateral movement.

Attack surface

Reached over the network via the PAN-OS management interface; the CVSS vector indicates no privileges and no user interaction are required. The description does not specify which management services or ports are involved, so defenders should treat any reachable management plane as exposed.

Exploitation

CVE-2017-15944 is listed in CISA KEV with a 2022-08-18 addition date, and public exploit code exists per Exploit-DB references. EPSS is 0.98303 (99.9th percentile), indicating very high predicted exploitation activity.

What to do

  • Upgrade PAN-OS to 6.1.19, 7.0.19, 7.1.14, 8.0.6 or later as applicable to the deployed branch.
  • Restrict management interface access to dedicated internal networks or jump hosts; never expose it to the internet.
  • Apply management plane access controls, allowed-IP lists and strong authentication while patching is in progress.
  • Monitor vendor advisories for the affected branch and confirm no unsupported versions remain in service.
  • Review firewall and management logs for unexpected access to the management interface.

Detection

  • Alert on management interface connections from untrusted or external source addresses.
  • Hunt for anomalous processes, shell activity or unexpected child processes on PAN-OS management plane.
  • Review authentication and configuration-change logs around management interface sessions for signs of tampering.
  • Correlate IDS/IPS signatures for known PAN-OS management interface exploit attempts against device logs.

This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.

Exploitation in the wild

CISA added CVE-2017-15944 to the Known Exploited Vulnerabilities catalog on 18 August 2022 as "Palo Alto Networks PAN-OS Remote Code Execution Vulnerability". Required action: Apply updates per vendor instructions. Federal deadline 8 September 2022.

Affected products

1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

LinkTags
http://www.securityfocus.com/bid/102079 Broken LinkThird Party AdvisoryVDB Entry
http://www.securitytracker.com/id/1040007 Broken LinkThird Party AdvisoryVDB Entry
https://security.paloaltonetworks.com/CVE-2017-15944 Vendor Advisory
https://www.exploit-db.com/exploits/43342/ ExploitThird Party AdvisoryVDB Entry
https://www.exploit-db.com/exploits/44597/ ExploitThird Party AdvisoryVDB Entry
http://www.securityfocus.com/bid/102079 Broken LinkThird Party AdvisoryVDB Entry
http://www.securitytracker.com/id/1040007 Broken LinkThird Party AdvisoryVDB Entry
https://security.paloaltonetworks.com/CVE-2017-15944 Vendor Advisory
https://www.exploit-db.com/exploits/43342/ ExploitThird Party AdvisoryVDB Entry
https://www.exploit-db.com/exploits/44597/ ExploitThird Party AdvisoryVDB Entry
https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2017-15944 US Government Resource

Track CVE-2017-15944 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

10.0CVE-2024-3400PAN-OS GlobalProtect command injection allows unauthenticated root code executionA command injection caused by arbitrary file creation in the GlobalProtect feature of Palo Alto Networks PAN-OS lets an unauthenticated attacker run …KEVEPSS 100%analysed10.0CVE-2020-2021PAN-OS SAML signature verification bypass allows authentication bypassPAN-OS fails to properly verify SAML signatures when SAML authentication is enabled and the 'Validate Identity Provider Certificate' option is unchec…KEVEPSS 4.4%analysed9.3CVE-2026-0300PAN-OS User-ID Authentication Portal buffer overflow allows root code executionA buffer overflow (out-of-bounds write, CWE-787) in the User-ID Authentication Portal (Captive Portal) service of Palo Alto Networks PAN-OS lets an u…KEVEPSS 32%analysed9.3CVE-2024-0012PAN-OS Management Web Interface Authentication BypassPAN-OS contains a missing authentication flaw (CWE-306) in the management web interface that lets an unauthenticated network attacker obtain PAN-OS a…KEVEPSS 100%analysed8.8CVE-2025-0108PAN-OS management web interface authentication bypassPAN-OS contains a missing-authentication flaw (CWE-306) in the management web interface that lets an unauthenticated attacker with network access inv…KEVEPSS 98%analysed8.7CVE-2024-3393PAN-OS DNS Security packet causes firewall reboot and maintenance modeA denial of service flaw in the DNS Security feature of Palo Alto Networks PAN-OS lets an unauthenticated attacker send a crafted packet through the …KEVEPSS 28%analysed8.6CVE-2022-0028PAN-OS URL filtering misconfiguration enables reflected TCP DoSA PAN-OS URL filtering policy misconfiguration allows a network-based attacker to use PA-Series, VM-Series and CN-Series firewalls to conduct reflect…KEVEPSS 2.4%analysed8.1CVE-2019-1579PAN-OS GlobalProtect pre-auth remote code executionPAN-OS versions 7.1.18, 8.0.11-h1 and 8.1.2 and earlier contain a remote code execution flaw (CWE-134, format string) that is reachable when the Glob…KEVEPSS 46%analysed

Source: NIST National Vulnerability Database (record CVE-2017-15944), CISA KEV, FIRST EPSS (scores of 2026-09-19). This page is refreshed as NVD updates the record.