CVE-2019-1575: Infoleak
Information disclosure in PAN-OS 7.1.23 and earlier, PAN-OS 8.0.18 and earlier, PAN-OS 8.1.8-h4 and earlier, and PAN-OS 9.0.2 and earlier may allow for an authenticated user with read-only privileges to extract the API key of the device and/or the username/password from the XML API (in PAN-OS) and possibly escalate privileges granted to them.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2019-1575?
CVE-2019-1575 has a medium severity level due to the potential information disclosure to authenticated users.
How do I fix CVE-2019-1575?
To fix CVE-2019-1575, upgrade your PAN-OS to version 7.1.24 or later, 8.0.19 or later, 8.1.9 or later, or 9.0.3 or later.
Who is affected by CVE-2019-1575?
CVE-2019-1575 affects any authenticated user with read-only privileges on impacted versions of PAN-OS.
What type of information can be disclosed by CVE-2019-1575?
CVE-2019-1575 may allow an authenticated user to extract the API key and username/password from the XML API.
What versions of PAN-OS are vulnerable to CVE-2019-1575?
PAN-OS versions 7.1.23 and earlier, 8.0.18 and earlier, 8.1.8-h4 and earlier, and 9.0.2 and earlier are vulnerable to CVE-2019-1575.