CVE-2017-5584: XSS
Cross-site scripting (XSS) vulnerability in the Management Web Interface in Palo Alto Networks PAN-OS 5.1, 6.x before 6.1.16, 7.0.x before 7.0.13, and 7.1.x before 7.1.8 allows remote authenticated users to inject arbitrary web script or HTML via unspecified vectors.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2017-5584?
CVE-2017-5584 is classified as a medium severity vulnerability due to its ability to allow remote authenticated users to execute arbitrary scripts.
How do I fix CVE-2017-5584?
To fix CVE-2017-5584, update your Palo Alto Networks PAN-OS to version 6.1.16 or later, or to version 7.0.13 or later.
What products are affected by CVE-2017-5584?
CVE-2017-5584 affects Palo Alto Networks PAN-OS versions 5.1, 6.x before 6.1.16, 7.0.x before 7.0.13, and 7.1.x before 7.1.8.
Is CVE-2017-5584 a remote code execution vulnerability?
No, CVE-2017-5584 is a cross-site scripting (XSS) vulnerability, not a remote code execution vulnerability.
Can an unauthenticated user exploit CVE-2017-5584?
No, CVE-2017-5584 requires that the attacker is a remote authenticated user to exploit the vulnerability.