A buffer overflow vulnerability in the User-ID Authentication Portal (Captive Portal) of Palo Alto Networks PAN-OS allows an unauthenticated, network-adjacent attacker to execute arbitrary code with root privileges by sending specially crafted packets. Affected versions include PAN-OS < 12.1.4-h5, < 11.2.4-h17, < 11.1.4-h33, and < 10.2.7-h34 on PA-Series and VM-Series firewalls with Captive Portal enabled. Cloud NGFW, Prisma Access, and Panorama are not affected.
Palo Alto Networks has confirmed limited active exploitation in the wild targeting internet-exposed Authentication Portals, with exploit automation confirmed. Organizations should apply the relevant hotfix immediately and, as an interim measure, restrict access to the Authentication Portal from untrusted networks and the public internet.
References:

