CVE-2019-1579
HIGH KEV RANSOMWAREPAN-OS < 7.1.19 - Unauthenticated Remote Code Execution via GlobalProtect Portal/Gateway Interface
Title source: manualExploitation Summary
CVE-2019-1579 is actively exploited and listed in the CISA Known Exploited Vulnerabilities (KEV) catalog, added January 10, 2022, with confirmed use in ransomware campaigns. EIP tracks 2 public exploits from researchers including securifera, Elsfa7-110.
AI-analyzed exploit summary This repository contains functional exploit code for CVE-2019-1579, a pre-auth RCE vulnerability in Palo Alto GlobalProtect SSL VPN. The exploit leverages a format string vulnerability to achieve arbitrary memory write and command execution on MIPS-based systems.
Description
Remote Code Execution in PAN-OS 7.1.18 and earlier, PAN-OS 8.0.11-h1 and earlier, and PAN-OS 8.1.2 and earlier with GlobalProtect Portal or GlobalProtect Gateway Interface enabled may allow an unauthenticated remote attacker to execute arbitrary code.
Exploits (2)
This repository contains functional exploit code for CVE-2019-1579, a pre-auth RCE vulnerability in Palo Alto GlobalProtect SSL VPN. The exploit leverages a format string vulnerability to achieve arbitrary memory write and command execution on MIPS-based systems.
This YAML file is a Nuclei template for detecting CVE-2019-1579, a pre-authentication RCE vulnerability in Palo Alto GlobalProtect. It checks for the presence of an 'Invalid parameters' message in the response from the '/sslmgr' endpoint, indicating a vulnerable instance.
References (5)
Scores
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H