First published: Tue Jul 16 2019(Updated: )
Information disclosure in PAN-OS 7.1.23 and earlier, PAN-OS 8.0.18 and earlier, PAN-OS 8.1.8-h4 and earlier, and PAN-OS 9.0.2 and earlier may allow for an authenticated user with read-only privileges to extract the API key of the device and/or the username/password from the XML API (in PAN-OS) and possibly escalate privileges granted to them.
Credit: psirt@paloaltonetworks.com
Affected Software | Affected Version | How to fix |
---|---|---|
Paloaltonetworks Pan-os | <7.1.24 | |
Paloaltonetworks Pan-os | >=8.0.0<8.0.19 | |
Paloaltonetworks Pan-os | >=8.1.0<8.1.8 | |
Paloaltonetworks Pan-os | >=9.0.0<=9.0.2 | |
Paloaltonetworks Pan-os | =8.1.8 | |
Paloaltonetworks Pan-os | =8.1.8-h4 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.