CVE-2018-10139: XSS
Published Aug 16, 2018
·Updated
The PAN-OS response for GlobalProtect Gateway in Palo Alto Networks PAN-OS 6.1.21 and earlier, PAN-OS 7.1.18 and earlier, PAN-OS 8.0.11 and earlier may allow an unauthenticated attacker to inject arbitrary JavaScript or HTML. PAN-OS 8.1 is NOT affected.
Affected Software
3 affected components
Palo Alto Networks PAN-OS<=6.1.21
Palo Alto Networks PAN-OS>=7.1.0<=7.1.18
Palo Alto Networks PAN-OS>=8.0.0<=8.0.11
Event History
Aug 16, 2018
CVE Published
via MITRE·06:00 PM
Data Sourced
via MITRE·06:00 PM
DescriptionWeakness
Frequently Asked Questions
1
What is the severity of CVE-2018-10139?
CVE-2018-10139 has a high severity rating due to its potential for allowing unauthenticated attackers to inject arbitrary JavaScript or HTML.
2
How do I fix CVE-2018-10139?
To fix CVE-2018-10139, upgrade to PAN-OS version 8.1 or later, as earlier versions are vulnerable.
3
Which versions of PAN-OS are affected by CVE-2018-10139?
CVE-2018-10139 affects PAN-OS 6.1.21 and earlier, 7.1.18 and earlier, and 8.0.11 and earlier.
4
Can CVE-2018-10139 be exploited remotely?
Yes, CVE-2018-10139 can be exploited remotely by unauthenticated attackers.
5
Is PAN-OS version 8.1 affected by CVE-2018-10139?
No, PAN-OS version 8.1 is not affected by CVE-2018-10139.