---
id: CVE-2019-1579
title: >-
  Remote Code Execution in PAN-OS 7.1.18 and earlier, PAN-OS 8.0.11-h1 and
  earlier, and PAN-OS 8.1.2 and earlier with GlobalProtect Portal or
  GlobalProtect Gateway Interface enabled may allow an unauthenticated remote
  attacker to execute a…
summary: >-
  Remote Code Execution in PAN-OS 7.1.18 and earlier, PAN-OS 8.0.11-h1 and
  earlier, and PAN-OS 8.1.2 and earlier with GlobalProtect Portal or
  GlobalProtect Gateway Interface enabled may allow an unauthenticated remote
  attacker to execute a…
severity: high
cvss: 8.1
cvssVector: 'CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H'
cwe:
  - CWE-134
  - CWE-134
vendor: paloaltonetworks
product: pan-os
affected:
  - pan-os < 7.1.19
  - 'pan-os >= 8.0.0, < 8.0.12'
  - 'pan-os >= 8.1.0, < 8.1.3'
patched:
  - pan-os 8.1.3
published: '2019-07-19'
updated: '2026-08-12'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2019-1579'
references:
  - url: 'http://www.securityfocus.com/bid/109310'
    label: psirt@paloaltonetworks.com
  - url: >-
      https://devco.re/blog/2019/07/17/attacking-ssl-vpn-part-1-PreAuth-RCE-on-Palo-Alto-GlobalProtect-with-Uber-as-case-study/
    label: psirt@paloaltonetworks.com
  - url: 'https://psirt.global.sonicwall.com/vuln-detail/SNWLID-2019-0010'
    label: psirt@paloaltonetworks.com
  - url: 'https://security.paloaltonetworks.com/CVE-2019-1579'
    label: psirt@paloaltonetworks.com
  - url: 'http://www.securityfocus.com/bid/109310'
    label: af854a3a-2127-422b-91ae-364da2661108
  - url: >-
      https://devco.re/blog/2019/07/17/attacking-ssl-vpn-part-1-PreAuth-RCE-on-Palo-Alto-GlobalProtect-with-Uber-as-case-study/
    label: af854a3a-2127-422b-91ae-364da2661108
  - url: 'https://psirt.global.sonicwall.com/vuln-detail/SNWLID-2019-0010'
    label: af854a3a-2127-422b-91ae-364da2661108
  - url: 'https://security.paloaltonetworks.com/CVE-2019-1579'
    label: af854a3a-2127-422b-91ae-364da2661108
  - url: >-
      https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2019-1579
    label: 134c704f-9b21-4f2e-91b3-4a467353bcc0
tags:
  - nvd
  - kev
  - in-the-wild
  - exploit-available
epss: 0.46239
epssPercentile: 0.98759
kev: true
kevDateAdded: '2022-01-10'
kevDueDate: '2022-07-10'
kevRansomware: true
exploited: true
ingestedAt: '2026-08-12T05:52:07.209Z'
exploits:
  github: 2
  githubRepos:
    - 'https://github.com/securifera/CVE-2019-1579'
    - 'https://github.com/Elsfa7-110/CVE-2019-1579'
  checkedAt: '2026-09-23T07:13:15.740Z'
exploitAvailable: true
---

## Overview

Remote Code Execution in PAN-OS 7.1.18 and earlier, PAN-OS 8.0.11-h1 and earlier, and PAN-OS 8.1.2 and earlier with GlobalProtect Portal or GlobalProtect Gateway Interface enabled may allow an unauthenticated remote attacker to execute arbitrary code.

## Affected

- `pan-os < 7.1.19`
- `pan-os >= 8.0.0, < 8.0.12`
- `pan-os >= 8.1.0, < 8.1.3`

## Remediation

Upgrade past the affected range:

- `pan-os 8.1.3`
