CVE-2016-3654: Palo Alto Networks PAN-OS

High severity, CVSS 7.2. EPSS: 2.6% chance of exploitation in the next 30 days.

The device management command line interface (CLI) in Palo Alto Networks PAN-OS before 5.0.18, 5.1.x before 5.1.11, 6.0.x before 6.0.13, 6.1.x before 6.1.10, and 7.0.x before 7.0.5H2 allows remote authenticated administrators to execute arbitrary OS commands via an SSH command parameter.

Affected products

  • Palo Alto Networks PAN-OS: from 5.0.0, before 5.0.18 (fixed in 5.0.18); from 5.1, before 5.1.11 (fixed in 5.1.11); from 6.0.0, before 6.0.13 (fixed in 6.0.13); from 6.1.0, before 6.1.10 (fixed in 6.1.10); from 7.0.0, up to and including 7.0.5

Published 2016-04-12. Last modified 2026-06-17.