CVE-2017-15940: Palo Alto Networks PAN-OS

Critical severity, CVSS 9.8. EPSS: 4.9% chance of exploitation in the next 30 days.

The web interface packet capture management component in Palo Alto Networks PAN-OS before 6.1.19, 7.0.x before 7.0.19, 7.1.x before 7.1.14, and 8.0.x before 8.0.6 allows remote authenticated users to execute arbitrary code via unspecified vectors.

Affected products

  • Palo Alto Networks PAN-OS: before 6.1.19 (fixed in 6.1.19); from 7.0.0, before 7.0.19 (fixed in 7.0.19); from 7.1.0, before 7.1.14 (fixed in 7.1.14); from 8.0.0, before 8.0.6 (fixed in 8.0.6)

Published 2017-12-11. Last modified 2026-06-17.