CVE-2019-1579

HIGH KEV RANSOMWARE

PAN-OS < 7.1.19 - Unauthenticated Remote Code Execution via GlobalProtect Portal/Gateway Interface

Title source: manual
STIX 2.1

Exploitation Summary

CVE-2019-1579 is actively exploited and listed in the CISA Known Exploited Vulnerabilities (KEV) catalog, added January 10, 2022, with confirmed use in ransomware campaigns. EIP tracks 2 public exploits from researchers including securifera, Elsfa7-110.

AI-analyzed exploit summary This repository contains functional exploit code for CVE-2019-1579, a pre-auth RCE vulnerability in Palo Alto GlobalProtect SSL VPN. The exploit leverages a format string vulnerability to achieve arbitrary memory write and command execution on MIPS-based systems.

Description

Remote Code Execution in PAN-OS 7.1.18 and earlier, PAN-OS 8.0.11-h1 and earlier, and PAN-OS 8.1.2 and earlier with GlobalProtect Portal or GlobalProtect Gateway Interface enabled may allow an unauthenticated remote attacker to execute arbitrary code.

Exploits (2)

nomisec WORKING POC 63 stars
by securifera · remote
https://github.com/securifera/CVE-2019-1579

This repository contains functional exploit code for CVE-2019-1579, a pre-auth RCE vulnerability in Palo Alto GlobalProtect SSL VPN. The exploit leverages a format string vulnerability to achieve arbitrary memory write and command execution on MIPS-based systems.

Classification
Working Poc 95%
Attack Type
Rce
Complexity
Complex
Reliability
Reliable
Target: Palo Alto GlobalProtect SSL VPN 8.0.7 (MIPS)
No auth needed
Prerequisites: Network access to the vulnerable SSL VPN interface · MIPS-based target system
devstral-2 · analyzed Feb 18, 2026 Full analysis →
nomisec SCANNER
by Elsfa7-110 · infoleak
https://github.com/Elsfa7-110/CVE-2019-1579

This YAML file is a Nuclei template for detecting CVE-2019-1579, a pre-authentication RCE vulnerability in Palo Alto GlobalProtect. It checks for the presence of an 'Invalid parameters' message in the response from the '/sslmgr' endpoint, indicating a vulnerable instance.

Classification
Scanner 90%
Attack Type
Rce
Complexity
Trivial
Reliability
Reliable
Target: Palo Alto GlobalProtect (versions affected by CVE-2019-1579)
No auth needed
Prerequisites: Network access to the target's GlobalProtect portal
devstral-2 · analyzed Feb 18, 2026 Full analysis →

References (5)

Core 5
Core References
Broken Link, Third Party Advisory, VDB Entry vdb-entry x_refsource_bid
http://www.securityfocus.com/bid/109310
Broken Link, Third Party Advisory x_refsource_confirm
https://psirt.global.sonicwall.com/vuln-detail/SNWLID-2019-0010
Vendor Advisory x_refsource_misc
https://security.paloaltonetworks.com/CVE-2019-1579

Scores

CVSS v3 8.1
EPSS 0.3932
EPSS Percentile 98.4%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H

CISA SSVC

Vulnrichment
Exploitation active
Automatable no
Technical Impact total

Details

CISA KEV 2022-01-10
VulnCheck KEV 2019-10-02
InTheWild.io 2019-12-02
ENISA EUVD EUVD-2019-10136
Ransomware Use Confirmed
CWE
CWE-134
Status published
Products (1)
paloaltonetworks/pan-os < 7.1.19
Published Jul 19, 2019
KEV Added Jan 10, 2022
Tracked Since Feb 18, 2026