CVE-2019-17440 is a critical vulnerability affecting Palo Alto Networks PA-7000 Series firewalls running specific PAN-OS 9.0 versions with a second-generation Switch Management Card and Log Forwarding Card. It allows an unauthenticated attacker with network access to the LFC to gain root access to the PAN-OS. This vulnerability carries a CVSS score of 9.8 (Critical) due to its network-based attack vector, low complexity, and complete compromise of confidentiality, integrity, and availability. While no public exploit code or Metasploit modules are available, and it is not listed in CISA KEV, the vulnerability did receive some community discussion and media coverage at the time of disclosure. Palo Alto Networks proactively addressed this with affected customers, and all identified customers have since upgraded.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
>= 9.0, < 9.0.5-h3CPE match | cpe:2.3:o:paloaltonetworks:pan-os:*:*:*:*:*:*:*:* | ||
>= 9.0, <= 9.0.5CPE matchmatch criteria | cpe:2.3:o:paloaltonetworks:pan-os:*:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.3 Bluesky, 0.3 Mastodon, and 2.4 GitHub mentions.
The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Remediation records are not available for this CVE.