OS Command Injection in Palo Alto PAN-OS - CVE-2021-3060
Published: November 11, 2021
Palo Alto PAN-OS
Palo Alto Networks, Inc.
Description
The vulnerability allows a remote attacker to execute arbitrary shell commands on the target system.
The vulnerability exists in the Simple Certificate Enrollment Protocol (SCEP) feature in PAN-OS. A remote non-authenticated attacker with specific knowledge of the firewall configuration to execute arbitrary code with root user privileges.