First published: Wed Jan 23 2019(Updated: )
The PAN-OS external dynamics lists in PAN-OS 7.1.21 and earlier, PAN-OS 8.0.14 and earlier, and PAN-OS 8.1.5 and earlier, may allow an attacker that is authenticated in Next Generation Firewall with write privileges to External Dynamic List configuration to inject arbitrary JavaScript or HTML.
Credit: psirt@paloaltonetworks.com psirt@paloaltonetworks.com
Affected Software | Affected Version | How to fix |
---|---|---|
Palo Alto Networks PAN-OS | <=7.1.21 | |
Palo Alto Networks PAN-OS | >=7.1.22<=8.0.14 | |
Palo Alto Networks PAN-OS | >=8.0.15<=8.1.5 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2019-1565 is considered a high severity vulnerability due to the potential for JavaScript or HTML injection by an authenticated user.
To mitigate CVE-2019-1565, upgrade your PAN-OS to versions 7.1.22, 8.0.15, or 8.1.6 or later.
CVE-2019-1565 affects users with write privileges to External Dynamic List configuration on PAN-OS 7.1.21 and earlier, 8.0.14 and earlier, and 8.1.5 and earlier.
CVE-2019-1565 can enable authenticated attackers to inject arbitrary JavaScript or HTML into the firewall's External Dynamic List configuration.
As of the last update, there have been no public disclosures of exploits leveraging CVE-2019-1565.