CVE Feed

    Dashboard / CVE / CVE-2019-17440

    CVE-2019-17440

    Improper restriction of communications to Log Forwarding Card (LFC) on PA-7000 Series devices with second-generation Switch Management Card (SMC) may allow an attacker with network access to the LFC to gain root access to PAN-OS. This issue affects PAN-OS 9.0 versions prior to 9.0.5-h3 on PA-7080 and PA-7050 devices with an LFC installed and configured. This issue does not affect PA-7000 Series deployments using the first-generation SMC and the Log Processing Card (LPC). This issue does not affect any other PA series devices. This issue does not affect devices without an LFC. This issue does not affect PAN-OS 8.1 or prior releases. This issue only affected a very limited number of customers and we undertook individual outreach to help them upgrade. At the time of publication, all identified customers have upgraded SW or content and are not impacted.

    Published:Dec 20, 2019
    Last Modified:Nov 21, 2024
    EPS:Dec 20, 2019
    EPSS Score:0.00372
    CVSS Score:10

    Affected Products

    Vendor
    Paloaltonetworks
    Product
    Pa-7050
    Vendor
    Paloaltonetworks
    Product
    Pa-7080
    Vendor
    Paloaltonetworks
    Product
    Pan-os

    Exploits

    No exploit reference

    Common Vulnerability Scoring System

    Attack Vector
    Network
    Adjacent
    Local
    Physical
    Privileges Required
    None
    Low
    High
    User Interaction
    None
    Required
    Scope
    Unchanged
    Changed
    Confidentiality
    None
    Low
    High
    Integrity
    None
    Low
    High
    Availability
    None
    Low
    High