New RCE on GlobalProtect if you didnt change the master key

Showing results for 
Show  only  | Search instead for 
Did you mean: 

New RCE on GlobalProtect if you didnt change the master key

Cyber Elite
Cyber Elite
Hello All,
I saw the below on twitter...
I wrote a tool to check master key configuration on palo alto firewalls and so far I haven't run into any instances of people actually changing the master key from p1a2l3o4a5l6t7o8

Community Team Member

Hi @OtakarKlier ,


Thanks for sharing this.

Adding the direct link from github:




LIVEcommunity team member, CISSP
Don't forget to hit that Like button if a post is helpful to you!

Cyber Elite
Cyber Elite

Thanks @kiwi ,

Also changing the master key does not require a reboot so it can be done at anytime. Just remember to add it to your password manager, if lost you'll need a factory reset the device :(.



Like what you see?

Show your appreciation!

Click Like if a post is helpful to you or if you just want to show your support.

Click Accept as Solution to acknowledge that the answer to your question has been provided.

The button appears next to the replies on topics you’ve started. The member who gave the solution and all future visitors to this topic will appreciate it!

These simple actions take just seconds of your time, but go a long way in showing appreciation for community members and the LIVEcommunity as a whole!

The LIVEcommunity thanks you for your participation!