Vulnerability record · CVE-2019-1579 · published 19 July 2019
CVE-2019-1579: PAN-OS GlobalProtect pre-auth remote code execution
Paloaltonetworks · Pan Os
PAN-OS versions 7.1.18, 8.0.11-h1 and 8.1.2 and earlier contain a remote code execution flaw (CWE-134, format string) that is reachable when the GlobalProtect Portal or Gateway interface is enabled. An unauthenticated remote attacker can execute arbitrary code on the firewall, which sits at the network edge and is a high-value target. The record does not describe the exact vulnerable code path beyond the format string classification.
Description
Remote Code Execution in PAN-OS 7.1.18 and earlier, PAN-OS 8.0.11-h1 and earlier, and PAN-OS 8.1.2 and earlier with GlobalProtect Portal or GlobalProtect Gateway Interface enabled may allow an unauthenticated remote attacker to execute arbitrary code.
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H
Automated analysis
critical priorityUnauthenticated network-reachable RCE on an edge firewall that is in CISA KEV with known ransomware use and very high EPSS.
What it is
PAN-OS versions 7.1.18, 8.0.11-h1 and 8.1.2 and earlier contain a remote code execution flaw (CWE-134, format string) that is reachable when the GlobalProtect Portal or Gateway interface is enabled. An unauthenticated remote attacker can execute arbitrary code on the firewall, which sits at the network edge and is a high-value target. The record does not describe the exact vulnerable code path beyond the format string classification.
Impact
Successful exploitation gives the attacker arbitrary code execution on the PAN-OS device, typically at high privilege, allowing full compromise of the firewall and any traffic or credentials it handles. Because the device is an edge security control, compromise can expose the internal network.
Attack surface
Reachable over the network via the GlobalProtect Portal or Gateway interface when that service is enabled; the CVSS vector shows no privileges and no user interaction required. Only internet-exposed or otherwise reachable GlobalProtect interfaces are at risk.
Exploitation
CVE-2019-1579 is listed in CISA KEV with known ransomware campaign use, and EPSS is 0.46 (98.7th percentile), indicating active exploitation is expected. A public exploit write-up is referenced, so weaponized code is available.
What to do
- Upgrade PAN-OS to a fixed release per the Palo Alto Networks advisory; 7.1.18, 8.0.11-h1 and 8.1.2 and earlier are affected.
- If patching cannot be done immediately, disable the GlobalProtect Portal and Gateway interfaces or restrict access to them to trusted sources.
- Place GlobalProtect interfaces behind access controls and monitor for anomalous requests to those endpoints.
- Treat any internet-facing PAN-OS device running an affected version as potentially compromised and review it for signs of intrusion.
- Track CISA KEV remediation due date (2022-07-10) and confirm closure.
Detection
- Review PAN-OS and GlobalProtect logs for unexpected process execution, crashes or restarts on the firewall.
- Monitor for unusual outbound connections or new listening services originating from the firewall itself.
- Hunt for exploitation attempts against GlobalProtect endpoints in web or proxy logs, including malformed requests.
- Check for unauthorized configuration changes, new admin accounts or persistence on PAN-OS devices.
This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.
Exploitation in the wild
CISA added CVE-2019-1579 to the Known Exploited Vulnerabilities catalog on 10 January 2022 as "Palo Alto Networks PAN-OS Remote Code Execution Vulnerability". CISA reports known use in ransomware campaigns. Required action: Apply updates per vendor instructions. Federal deadline 10 July 2022.
Affected products
1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.
References
| Link | Tags |
|---|---|
| http://www.securityfocus.com/bid/109310 | Broken LinkThird Party AdvisoryVDB Entry |
| https://devco.re/blog/2019/07/17/attacking-ssl-vpn-part-1-PreAuth-RCE-on-Palo-Alto-GlobalProtect-with-Uber-as-case-study | ExploitThird Party Advisory |
| https://psirt.global.sonicwall.com/vuln-detail/SNWLID-2019-0010 | Broken LinkThird Party Advisory |
| https://security.paloaltonetworks.com/CVE-2019-1579 | Vendor Advisory |
| http://www.securityfocus.com/bid/109310 | Broken LinkThird Party AdvisoryVDB Entry |
| https://devco.re/blog/2019/07/17/attacking-ssl-vpn-part-1-PreAuth-RCE-on-Palo-Alto-GlobalProtect-with-Uber-as-case-study | ExploitThird Party Advisory |
| https://psirt.global.sonicwall.com/vuln-detail/SNWLID-2019-0010 | Broken LinkThird Party Advisory |
| https://security.paloaltonetworks.com/CVE-2019-1579 | Vendor Advisory |
| https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2019-1579 | US Government Resource |
Track CVE-2019-1579 inside VULONE
Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.
Related vulnerabilities
Same products first, then exploited flaws of the same weakness class.
Source: NIST National Vulnerability Database (record CVE-2019-1579), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.