LiveBreach Intelligence: data breaches, leaks & ransomware, tracked as they surfaceOngoing protection: GalaxyWarden →
Recent BreachesData breach tracker

CVE-2019-1579: Palo Alto Networks PAN-OS Remote Code Execution Vulnerability

RBRecent Breaches Vulnerability Intelligence·Jan 10, 2022
Critical⚠ Actively exploited (CISA KEV)Ransomware-linked
Critical
Severity
Active
CISA KEV
Yes
Ransomware use
Jul 10, 2022
Patch deadline
⚠ Exploited in the wild. CISA added CVE-2019-1579 to its Known Exploited Vulnerabilities catalog on Jan 10, 2022, with a federal patch deadline of Jul 10, 2022 — meaning attackers are actively using it. If you run the affected software, patch it immediately. Ransomware crews are known to exploit this flaw.

Remote Code Execution in PAN-OS with GlobalProtect Portal or GlobalProtect Gateway Interface enabled.

CVE-2019-1579 is a remote code execution vulnerability in Palo Alto Networks PAN-OS when the GlobalProtect Portal or GlobalProtect Gateway interface is enabled. It matters because successful abuse can let an unauthenticated attacker run code on the firewall itself, giving a foothold on a device that sits at the network edge and often holds privileged access to internal resources. CISA notes known ransomware use, so organizations still running affected configurations should treat this as a high-priority exposure.

How it works

The underlying weakness is CWE-134, use of an externally controlled format string. In products of this class, user-supplied input reaches a formatting function without proper sanitization. An attacker who can reach the GlobalProtect Portal or Gateway interface can craft input that influences how the format string is interpreted, leading to memory corruption and ultimately arbitrary code execution on the PAN-OS device. Public detail on exact exploit mechanics is limited; defenders should treat any unauthenticated interaction with the enabled GlobalProtect interfaces as potentially dangerous and confirm full technical specifics against the vendor advisory.

Am I affected? How to find it in your systems

PAN-OS runs on Palo Alto Networks next-generation firewalls and related appliances. GlobalProtect Portal and Gateway services are commonly exposed to the internet to support remote-access VPN. Inventory every PAN-OS device, note whether GlobalProtect Portal or Gateway is enabled, and record the exact software version. Compare those versions and feature states against the fixed releases listed in the Palo Alto Networks advisory for CVE-2019-1579; do not rely on version ranges stated elsewhere.

Telemetry signs of exploitation are not exhaustively documented in the supplied facts; treat unexplained reboots, new admin accounts, or outbound connections from the firewall management plane as suspicious and investigate promptly.

How to remediate

Patch first. Apply the updates Palo Alto Networks released for this vulnerability, following the vendor’s installation and reboot guidance exactly. CISA’s required action is to apply updates per vendor instructions. After patching, verify the new version string on each device and confirm GlobalProtect services function as expected.

If you can't patch immediately

Reduce exposure until the vendor update can be installed. Compensating controls for this class of edge RCE include:

These measures lower risk but do not replace the patch.

If your data may have been exposed

Actively exploited vulnerabilities, especially those with documented ransomware use, frequently precede broader compromise and data theft. If you discover that an unpatched GlobalProtect-enabled system was reachable during the period of known exploitation, assume potential access, begin incident-response procedures, and examine logs for lateral movement or exfiltration. As a quick additional check, you can run a free exposure scan of your email addresses against known breach data sets to see whether credentials or personal information have already appeared in public dumps.

AICompiled with AI assistance from public sources and published under our editorial standards.

Details

AffectedPalo Alto Networks · PAN-OS
WeaknessCWE-134
Added to CISA KEVJan 10, 2022
Federal patch deadlineJul 10, 2022
Known ransomware useYes
Check if your data is exposed →

Official records: NVD · CISA KEV

← All actively-exploited vulnerabilities