First published: Thu Aug 16 2018(Updated: )
The PAN-OS Management Web Interface in Palo Alto Networks PAN-OS 8.1.2 and earlier may allow an authenticated user to shut down all management sessions, resulting in all logged in users to be redirected to the login page. PAN-OS 6.1, PAN-OS 7.1 and PAN-OS 8.0 are NOT affected.
Credit: psirt@paloaltonetworks.com
Affected Software | Affected Version | How to fix |
---|---|---|
Palo Alto Networks PAN-OS | >=8.1.0<=8.1.2 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2018-10140 is considered to have a high severity due to its impact on user management sessions.
To fix CVE-2018-10140, upgrade your PAN-OS to version 8.1.3 or later.
CVE-2018-10140 affects users of Palo Alto Networks PAN-OS versions 8.1.0 to 8.1.2.
Exploitation of CVE-2018-10140 allows an authenticated user to terminate all active management sessions.
There are no documented workarounds for CVE-2018-10140 other than updating to a patched version.