CVE-2021-3047: PAN-OS: Weak Cryptography Used in Web Interface Authentication
A cryptographically weak pseudo-random number generator (PRNG) is used during authentication to the Palo Alto Networks PAN-OS web interface. This enables an authenticated attacker, with the capability to observe their own authentication secrets over a long duration on the PAN-OS appliance, to impersonate another authenticated web interface administrator's session. This issue impacts: PAN-OS 8.1 versions earlier than PAN-OS 8.1.19; PAN-OS 9.0 versions earlier than PAN-OS 9.0.14; PAN-OS 9.1 versions earlier than PAN-OS 9.1.10; PAN-OS 10.0 versions earlier than PAN-OS 10.0.4. PAN-OS 10.1 versions are not impacted.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
Palo Alto Networks PAN-OSto a version that resolves this vulnerability.Fixed in 8.1.19 - Upgrade
Upgrade
Palo Alto Networks PAN-OSto a version that resolves this vulnerability.Fixed in 9.0.14 - Upgrade
Upgrade
Palo Alto Networks PAN-OSto a version that resolves this vulnerability.Fixed in 9.1.10 - Upgrade
Upgrade
Palo Alto Networks PAN-OSto a version that resolves this vulnerability.Fixed in 10.0.4
Event History
Frequently Asked Questions
What is CVE-2021-3047?
CVE-2021-3047 refers to a vulnerability in the Palo Alto Networks PAN-OS web interface where a weak pseudo-random number generator (PRNG) is used during authentication.
What is the severity of CVE-2021-3047?
The severity of CVE-2021-3047 is medium with a severity value of 3.1.
How does CVE-2021-3047 impact Palo Alto Networks PAN-OS?
CVE-2021-3047 allows an authenticated attacker to impersonate other users if they can observe their own authentication secrets over a long duration on the PAN-OS appliance.
Which versions of Palo Alto Networks PAN-OS are affected by CVE-2021-3047?
CVE-2021-3047 affects Palo Alto Networks PAN-OS versions 8.1.0 to 8.1.19, 9.0.0 to 9.0.14, 9.1.0 to 9.1.10, and 10.0.0 to 10.0.4.
How can I fix CVE-2021-3047 in Palo Alto Networks PAN-OS?
To fix CVE-2021-3047, Palo Alto Networks recommends upgrading to a fixed software release.