Palo Alto Networks PAN-OS GlobalProtect Web Portal RCE (PAN-SA-2016-0005)

This script is Copyright (C) 2016 Tenable Network Security, Inc.

Synopsis :

The remote host is affected by a remote code execution vulnerability.

Description :

The Palo Alto Networks PAN-OS running on the remote host is affected
by a remote code execution vulnerability in the GlobalProtect web
portal due to improper validation of user-supplied input when handling
SSL VPN requests. An unauthenticated, remote attacker can exploit
this, via a crafted request, to cause an overflow condition, resulting
in a denial of service or the execution of arbitrary code.

Note that the remote PAN-OS is reportedly affected by other
vulnerabilities as well; however, Nessus has not tested for these.

See also :

Solution :

Upgrade to Palo Alto Networks PAN-OS version 5.0.18 / 6.0.13 /
6.1.10 / 7.0.5 or later.

Risk factor :

Critical / CVSS Base Score : 10.0
CVSS Temporal Score : 8.3
Public Exploit Available : true

Family: General

Nessus Plugin ID: 90246 ()

Bugtraq ID:

CVE ID: CVE-2016-3657

Ready to Amp Up Your Nessus Experience?

Get Nessus Professional to scan unlimited IPs, run compliance checks & more

Buy Nessus Professional Now