CVE-2019-1579
KEV RANSOMWAREHIGH 8.1EPSS 46.2%
Remote Code Execution in PAN-OS 7.1.18 and earlier, PAN-OS 8.0.11-h1 and earlier, and PAN-OS 8.1.2 and earlier with GlobalProtect Portal or GlobalProtect Gateway Interface enabled may allow an unauthenticated remote attacker to execute arbitrary code.
- CVSS v3.1
- 8.1 HIGH
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H - CVSS v3.1
- 8.1 HIGH
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H - CVSS v2.0
- 6.8 MEDIUM
AV:N/AC:M/Au:N/C:P/I:P/A:P - EPSS
- 46.24% chance of exploitation in the next 30 days, 99th percentile
- CISA KEV
- added 2022-01-10, used in ransomware campaigns
- Nuclei
- high · CWE-134
- Published
- 2019-07-19
- Updated
- 2026-08-12
Proof-of-concept exploits (3)
- https://devco.re/blog/2019/07/17/attacking-ssl-vpn-part-1-PreAuth-RCE-on-Palo-Alto-Global…
- Elsfa7-110/CVE-2019-15790★ · 2020-10-21
- securifera/CVE-2019-157961★ · 2019-09-10