CVE-2019-1579
Executive Summary
CVE-2019-1579 allows unauthenticated remote attackers to execute arbitrary code on PAN-OS 7.1.18 and earlier, PAN-OS 8.0.11-h1 and earlier, and PAN-OS 8.1.2 and earlier when GlobalProtect Portal or Gateway Interface is enabled. The vulnerability is actively exploited (CISA KEV), posing a critical risk to network perimeter devices and VPN endpoints.
Authoritative CVE Metadata - CVSS Base Score: 8.1 (HIGH) - Published: 2019-07-19T22:15:11.557 - Last Modified: 2026-10-02T04:18:01.077
[!CAUTION] Known Exploited Vulnerability: YES (CISA KEV Added: 2022-01-10)
Original Description: Remote Code Execution in PAN-OS 7.1.18 and earlier, PAN-OS 8.0.11-h1 and earlier, and PAN-OS 8.1.2 and earlier with GlobalProtect Portal or GlobalProtect Gateway Interface enabled may allow an unauthenticated remote attacker to execute arbitrary code.
"The real measure of your wealth is how much youd be worth if you lost all your money."
— Unknown