CVE-2019-1580 is a critical memory corruption vulnerability affecting Palo Alto Networks PAN-OS versions 7.1.24 and earlier, 8.0.19 and earlier, 8.1.9 and earlier, and 9.0.3 and earlier. This flaw allows a remote, unauthenticated attacker to craft a malicious message to the Secure Shell Daemon (SSHD), leading to arbitrary memory corruption. With a CVSS score of 9.8 (CRITICAL), it presents a severe risk due to its network-based attack vector, low attack complexity, and high potential for confidentiality, integrity, and availability impacts. While there is no evidence of active exploitation, public exploit code, or KEV listing, the vulnerability has garnered significant community discussion with 11 mentions and media coverage in one article.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
<= 7.1.24CPE matchmatch criteria | cpe:2.3:o:paloaltonetworks:pan-os:*:*:*:*:*:*:*:* | ||
>= 8.0.0, <= 8.0.19CPE matchmatch criteria | cpe:2.3:o:paloaltonetworks:pan-os:*:*:*:*:*:*:*:* | ||
>= 8.1.0, <= 8.1.9CPE matchmatch criteria | cpe:2.3:o:paloaltonetworks:pan-os:*:*:*:*:*:*:*:* | ||
>= 9.0.0, <= 9.0.3CPE matchmatch criteria | cpe:2.3:o:paloaltonetworks:pan-os:*:*:*:*:*:*:*:* |
CVSS version used by this source: 3.0
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.3 Bluesky, 0.3 Mastodon, and 2.4 GitHub mentions.
The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Remediation records are not available for this CVE.