LiveBreach Intelligence: data breaches, leaks & ransomware, tracked as they surfaceOngoing protection: GalaxyWarden →
Recent BreachesData breach tracker

CVE-2017-15944: Palo Alto Networks PAN-OS Remote Code Execution Vulnerability

RBRecent Breaches Vulnerability Intelligence·Aug 18, 2022
High⚠ Actively exploited (CISA KEV)
High
Severity
Active
CISA KEV
No
Ransomware use
Sep 8, 2022
Patch deadline
⚠ Exploited in the wild. CISA added CVE-2017-15944 to its Known Exploited Vulnerabilities catalog on Aug 18, 2022, with a federal patch deadline of Sep 8, 2022 — meaning attackers are actively using it. If you run the affected software, patch it immediately.

Palo Alto Networks PAN-OS contains multiple, unspecified vulnerabilities which can allow for remote code execution when chained.

CVE-2017-15944 is a remote code execution issue in Palo Alto Networks PAN-OS. According to CISA, PAN-OS contains multiple unspecified vulnerabilities that can allow remote code execution when chained. This matters because PAN-OS runs on network security appliances that often sit at the edge or in critical paths; successful abuse can give an attacker control of the device and a foothold into the rest of the environment.

Defenders should treat this as a high-priority patching item for any PAN-OS deployment until the vendor advisory confirms the system is not in scope. Specifics such as exact versions and attack preconditions must be confirmed against the vendor advisory.

How it works

The CWE for this CVE is not specified in the available record. CISA describes the issue as multiple unspecified vulnerabilities in Palo Alto Networks PAN-OS that can be chained to achieve remote code execution. In general terms for this product class, that means an unauthenticated or lightly authenticated remote attacker can send crafted requests to exposed management or service interfaces and, by combining flaws, run code with the privileges of the affected process or the device itself.

No public exploit mechanics, payloads, or step-by-step abuse details are provided in the given facts. Do not assume a particular interface, protocol, or authentication bypass; verify the precise attack surface and preconditions in the vendor advisory. The practical takeaway is that chaining several weaknesses can turn limited access into full remote code execution on the firewall or related PAN-OS appliance.

Am I affected? How to find it in your systems

PAN-OS is the operating system on Palo Alto Networks firewalls and related security appliances. These devices commonly sit at internet edges, in data-center perimeters, as internal segmentation firewalls, or in virtual form in cloud and private cloud environments.

If you cannot confirm version status quickly, treat internet-facing or broadly reachable PAN-OS instances as potentially affected until the advisory clears them.

How to remediate

Patch first. Apply the updates specified by Palo Alto Networks for CVE-2017-15944, following the vendor’s instructions exactly. CISA’s required action is to apply updates per vendor instructions.

Confirm every remediation step against the official vendor advisory; do not assume version ranges or workaround applicability from secondary sources.

If you can't patch immediately

When immediate patching is not possible, reduce exposure with compensating controls while you plan the update.

These measures lower risk but do not replace the vendor update. Track the advisory and apply the official fix as soon as you can.

If your data may have been exposed

Actively exploited remote code execution vulnerabilities on network appliances can lead to full device compromise, credential theft, traffic interception, and lateral movement that results in data breaches. Known ransomware use is not documented for this CVE in the provided facts; still treat any confirmed compromise as a potential incident.

If you suspect exposure, follow your incident response process: isolate affected systems, preserve logs and images, rotate credentials that may have traversed the device, and assess what traffic or data the appliance could have accessed. You can also run a free exposure scan of your email addresses against known breach data to check whether your identities already appear in public breach corpora, then prioritize password resets and monitoring accordingly.

AICompiled with AI assistance from public sources and published under our editorial standards.

Details

AffectedPalo Alto Networks · PAN-OS
Added to CISA KEVAug 18, 2022
Federal patch deadlineSep 8, 2022
Known ransomware useNot documented
Check if your data is exposed →

Official records: NVD · CISA KEV

← All actively-exploited vulnerabilities