CVE-2016-3654

Severity CVSS v4.0:
Pending analysis
Type:
CWE-20 Input Validation
Publication date:
12/04/2016
Last modified:
12/04/2025

Description

The device management command line interface (CLI) in Palo Alto Networks PAN-OS before 5.0.18, 5.1.x before 5.1.11, 6.0.x before 6.0.13, 6.1.x before 6.1.10, and 7.0.x before 7.0.5H2 allows remote authenticated administrators to execute arbitrary OS commands via an SSH command parameter.

Vulnerable products and versions

CPE From Up to
cpe:2.3:o:paloaltonetworks:pan-os:*:*:*:*:*:*:*:* 5.0.0 (including) 5.0.18 (excluding)
cpe:2.3:o:paloaltonetworks:pan-os:*:*:*:*:*:*:*:* 5.1 (including) 5.1.11 (excluding)
cpe:2.3:o:paloaltonetworks:pan-os:*:*:*:*:*:*:*:* 6.0.0 (including) 6.0.13 (excluding)
cpe:2.3:o:paloaltonetworks:pan-os:*:*:*:*:*:*:*:* 6.1.0 (including) 6.1.10 (excluding)
cpe:2.3:o:paloaltonetworks:pan-os:*:*:*:*:*:*:*:* 7.0.0 (including) 7.0.5 (including)