First published: Wed Jan 30 2019(Updated: )
The PAN-OS management web interface in PAN-OS 7.1.21 and earlier, PAN-OS 8.0.14 and earlier, and PAN-OS 8.1.5 and earlier, may allow an unauthenticated attacker to inject arbitrary JavaScript or HTML.
Credit: psirt@paloaltonetworks.com psirt@paloaltonetworks.com
Affected Software | Affected Version | How to fix |
---|---|---|
Palo Alto Networks PAN-OS | >=7.1.0<7.1.22 | |
Palo Alto Networks PAN-OS | >=8.0.0<8.0.15 | |
Palo Alto Networks PAN-OS | >=8.1.0<8.1.6 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2019-1566 is classified as a high-severity vulnerability due to the potential for unauthenticated attackers to inject arbitrary JavaScript or HTML.
To mitigate CVE-2019-1566, upgrade PAN-OS to version 7.1.22, 8.0.15, or 8.1.6 or later.
CVE-2019-1566 affects Palo Alto Networks PAN-OS versions 7.1.21 and earlier, 8.0.14 and earlier, and 8.1.5 and earlier.
Exploitation of CVE-2019-1566 allows attackers to execute arbitrary JavaScript or HTML, potentially leading to data theft or system compromise.
Yes, CVE-2019-1566 is a remote vulnerability that can be exploited without authentication.