Record summary

CVE-2021-3060 has a selected CVSS score of 8.1 (high); EIP currently links 1 repository PoC.

Description

An OS command injection vulnerability in the Simple Certificate Enrollment Protocol (SCEP) feature of PAN-OS software allows an unauthenticated network-based attacker with specific knowledge of the firewall configuration to execute arbitrary code with root user privileges. The attacker must have network access to the GlobalProtect interfaces to exploit this issue. This issue impacts: PAN-OS 8.1 versions earlier than PAN-OS 8.1.20-h1; PAN-OS 9.0 versions earlier than PAN-OS 9.0.14-h3; PAN-OS 9.1 versions earlier than PAN-OS 9.1.11-h2; PAN-OS 10.0 versions earlier than PAN-OS 10.0.8; PAN-OS 10.1 versions earlier than PAN-OS 10.1.3. Prisma Access customers with Prisma Access 2.1 Preferred and Prisma Access 2.1 Innovation firewalls are impacted by this issue.

Description source: CVE List

Exploitation context

Available material

Repository PoCs
1

Affected products and versions

2
ProductSourceVersion rangeStatus
CVE List8.1 to < 8.1.20-h1affected
9.0 to < 9.0.14-h3affected
9.1 to < 9.1.11-h2affected
10.0 to < 10.0.8affected
10.1 to < 10.1.3affected
CVE List2.1 Preferredaffected
2.1 Innovationaffected
All versionsunaffected

Proofs of concept

1

Repository PoCs

GitHubanmolksachan/CVE-2021-3060Repository PoCby anmolksachanStars: 0Not analyzed3 files

13.2 KiB

GitHub

PoC details

References

4