Sploitus

Exploit for OS Command Injection in Paloaltonetworks Pan-Os

githubexploit · 2022-08-03

Exploit Code

README18 lines
## https://sploitus.com/exploit?id=F7870446-F1DD-554D-8C11-F3DD3AF017ED
# CVE-2020-2038
Exploit to capitalize on vulnerability CVE-2020-2038.

According to Palo Alto Networks:
_An OS Command Injection vulnerability in the PAN-OS management interface that allows authenticated administrators to execute arbitrary OS commands with root privileges._

This issue impacts:
PAN-OS 9.0 versions earlier than 9.0.10
PAN-OS 9.1 versions earlier than 9.1.4
PAN-OS 10.0 versions earlier than 10.0.1

# Demo
[![demo](https://raw.githubusercontent.com/und3sc0n0c1d0/CVE-2020-2038/main/demo.gif)]

# Credits
All credits go to Mikhail Klyuchnikov and Nikita Abramov of Positive Technologies who are the researchers who discovered this vulnerability.
More info: https://swarm.ptsecurity.com/swarm-of-palo-alto-pan-os-vulnerabilities/