Multiple vulnerabilities exist in Palo Alto Networks products that could allow an attacker to bypass security controls, gain elevated privileges, execute arbitrary commands or code, access sensitive information, manipulate protected resources or files, perform cross-site scripting (XSS) attacks, disrupt system availability through reboot conditions, or route network traffic outside the intended VPN tunnel.
Target Audience:
All organizations and administrators using affected Palo Alto Networks products.
Risk Assessment:
High risk of unauthorized access, privilege escalation, arbitrary command or code execution, information disclosure, security control bypass, unauthorized file manipulation, cross-site scripting (XSS), VPN traffic bypass, and service disruption.
Impact Assessment:
Unauthorized access to sensitive information, arbitrary code execution, manipulation of protected resources and files, disruption of service, bypass of VPN security controls, exposure of confidential data, and full system compromise.
The information provided herein is on "as is" basis, without warranty of any kind.