CVE-2023-6795: Palo Alto Networks PAN-OS

Medium severity, CVSS 4.7. EPSS: 1.1% chance of exploitation in the next 30 days.

An OS command injection vulnerability in Palo Alto Networks PAN-OS software enables an authenticated administrator to disrupt system processes and potentially execute arbitrary code with limited privileges on the firewall.

Affected products

  • Palo Alto Networks PAN-OS: from 8.1.0, before 8.1.24 (fixed in 8.1.24); from 9.0.0, before 9.0.17 (fixed in 9.0.17); from 9.1.0, before 9.1.12 (fixed in 9.1.12); from 10.0.0, before 10.0.9 (fixed in 10.0.9); from 10.1.0, before 10.1.3 (fixed in 10.1.3)

Published 2023-12-13. Last modified 2026-06-17.