First published: Tue Jun 02 2015(Updated: )
XML external entity (XXE) vulnerability in the management interface in PAN-OS before 5.0.16, 6.x before 6.0.8, and 6.1.x before 6.1.4 allows remote authenticated administrators to obtain sensitive information via crafted XML data.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Palo Alto Networks PAN-OS | <=5.0.15 | |
Palo Alto Networks PAN-OS | =6.0 | |
Palo Alto Networks PAN-OS | =6.0.1 | |
Palo Alto Networks PAN-OS | =6.0.2 | |
Palo Alto Networks PAN-OS | =6.0.3 | |
Palo Alto Networks PAN-OS | =6.0.4 | |
Palo Alto Networks PAN-OS | =6.0.5 | |
Palo Alto Networks PAN-OS | =6.0.6 | |
Palo Alto Networks PAN-OS | =6.0.7 | |
Palo Alto Networks PAN-OS | =6.1.0 | |
Palo Alto Networks PAN-OS | =6.1.1 | |
Palo Alto Networks PAN-OS | =6.1.2 | |
Palo Alto Networks PAN-OS | =6.1.3 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2015-4162 has been classified as a medium severity vulnerability due to its potential to allow sensitive information disclosure.
To fix CVE-2015-4162, you should upgrade to PAN-OS versions 5.0.16, 6.0.8, or 6.1.4 or later.
CVE-2015-4162 affects Palo Alto Networks PAN-OS versions prior to 5.0.16, and specific 6.x versions before 6.0.8 and 6.1.x before 6.1.4.
An XML external entity (XXE) vulnerability allows an attacker to interfere with the processing of XML data, potentially enabling retrieval of sensitive data.
CVE-2015-4162 can be exploited by remote authenticated administrators who are able to send crafted XML data to the management interface.