CVE-2019-1579 RCE in PAN-OS with GlobalProtect Portal or Gateway Interface

Vulnerability Details

Basic Information

Title CVE-2019-1579 RCE in PAN-OS with GlobalProtect Portal or Gateway Interface
Type attackerkb
Published 2025-04-26T00:00:00
Last Seen 2025-04-26T21:56:14
CVSS Score 8.1 (HIGH)

CVSS v3 Details

Attack Vector NETWORK
Attack Complexity HIGH
Privileges Required NONE
User Interaction NONE
Scope UNCHANGED
Confidentiality Impact HIGH
Integrity Impact HIGH
Availability Impact HIGH

CVE Information

CVE IDs CVE-2019-1579
CWE
Bulletin Family info

Description

Remote Code Execution in PAN-OS 7.1.18 and earlier, PAN-OS 8.0.11-h1 and earlier, and PAN-OS 8.1.2 and earlier with GlobalProtect Portal or GlobalProtect Gateway Interface enabled may allow an unauthenticated remote attacker to execute arbitrary code.

**Recent assessments:**

**bcook-r7** at June 05, 2020 1:28pm UTC reported:

Based on the great research work by Orange Tsai, exploiting this vulnerability is made fairly trivial. Adding exploited in the wild based on notes from EU CERT https://media.cert.europa.eu/static/SecurityAdvisories/2019/CERT-EU-SA2019-017.pdf . Since this is VPN software, it’s often keys to the kingdom. Hope everyone has patched by now.

Assessed Attacker Value: 5
Assessed Attacker Value: 5Assessed Attacker Value: 5

Impact Assessment

Base Score 8.1
Severity HIGH

πŸ’­ Join the Security Discussion

πŸ”’ Your email address will not be published. Required fields are marked *

⚠️ Please be respectful and constructive in your comments. Security discussions should remain professional.