CVE-2018-9335: XSS
Published Jul 3, 2018
·Updated
The PAN-OS session browser in PAN-OS 6.1.20 and earlier, PAN-OS 7.1.16 and earlier, PAN-OS 8.0.9 and earlier, and PAN-OS 8.1.1 and earlier may allow an attacker to inject arbitrary JavaScript or HTML.
Affected Software
4 affected components
Palo Alto Networks PAN-OS>6.0.0<=6.1.20
Palo Alto Networks PAN-OS>=7.1.0<=7.1.16
Palo Alto Networks PAN-OS>8.0.0<=8.0.9
Palo Alto Networks PAN-OS>=8.1.0<=8.1.1
Event History
Jul 3, 2018
CVE Published
via MITRE·09:00 PM
Data Sourced
via MITRE·09:00 PM
Description
Data Sourced
via NVD·09:29 PM
DescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2018-9335?
CVE-2018-9335 has a high severity rating due to its potential to allow arbitrary JavaScript or HTML injection.
2
How do I fix CVE-2018-9335?
To fix CVE-2018-9335, upgrade the PAN-OS to a version later than 8.1.1, 8.0.9, 7.1.16, or 6.1.20.
3
Which versions of PAN-OS are affected by CVE-2018-9335?
CVE-2018-9335 affects PAN-OS versions 6.1.20 and earlier, 7.1.16 and earlier, 8.0.9 and earlier, and 8.1.1 and earlier.
4
What type of attack does CVE-2018-9335 facilitate?
CVE-2018-9335 facilitates a cross-site scripting (XSS) attack through JavaScript or HTML injection.
5
Is there a workaround for CVE-2018-9335?
There is no known workaround for CVE-2018-9335; the recommended action is to update to a secure version of PAN-OS.