CVE-2021-3037: PAN-OS: Secrets for scheduled configuration exports are logged in system logs
An information exposure through log file vulnerability exists in Palo Alto Networks PAN-OS software where the connection details for a scheduled configuration export are logged in system logs. Logged information includes the cleartext username, password, and IP address used to export the PAN-OS configuration to the destination server.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
Palo Alto Networks PAN-OSto a version that resolves this vulnerability.Fixed in 8.1.19 - Upgrade
Upgrade
Palo Alto Networks PAN-OSto a version that resolves this vulnerability.Fixed in 9.0.13 - Upgrade
Upgrade
Palo Alto Networks PAN-OSto a version that resolves this vulnerability.Fixed in 9.1.4 - Configuration
After upgrading the PAN-OS appliance, change the connection details used in scheduled configuration exports so that the cleartext username/password/IP previously logged in system logs are not reused.
PAN-OS scheduled configuration exports connection details used in scheduled configuration exports = change to new/updated credentials and destination connection info - Operational
Change the credentials on the destination server that are used to export the PAN-OS configuration.
Event History
Frequently Asked Questions
What is the severity of CVE-2021-3037?
The severity of CVE-2021-3037 is low with a CVSS score of 2.3.
How does the information exposure through log file vulnerability in Palo Alto Networks PAN-OS software work?
The vulnerability allows the cleartext username, password, and IP address used for a scheduled configuration export to be logged in system logs, exposing sensitive information.
Which versions of Palo Alto Networks PAN-OS software are affected by CVE-2021-3037?
Versions 8.1.0 to 8.1.19, 9.0.0 to 9.0.13, and 9.1.0 to 9.1.4 of Palo Alto Networks PAN-OS software are affected by CVE-2021-3037.
How can I fix the information exposure through log file vulnerability in Palo Alto Networks PAN-OS software?
Upgrade to a fixed version of Palo Alto Networks PAN-OS software (8.1.20, 9.0.14, or 9.1.5) to fix the vulnerability.
Where can I find more information about CVE-2021-3037?
You can find more information about CVE-2021-3037 on the Palo Alto Networks security website.