CVE-2021-3052: PAN-OS: Reflected Cross-Site Scripting (XSS) in Web Interface
A reflected cross-site scripting (XSS) vulnerability in the Palo Alto Network PAN-OS web interface enables an authenticated network-based attacker to mislead another authenticated PAN-OS administrator to click on a specially crafted link that performs arbitrary actions in the PAN-OS web interface as the targeted authenticated administrator. This issue impacts: PAN-OS 8.1 versions earlier than 8.1.20; PAN-OS 9.0 versions earlier than 9.0.14; PAN-OS 9.1 versions earlier than 9.1.10; PAN-OS 10.0 versions earlier than 10.0.2. This issue does not affect Prisma Access.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
Palo Alto Networks PAN-OSto a version that resolves this vulnerability.Fixed in 8.1.20 - Upgrade
Upgrade
Palo Alto Networks PAN-OSto a version that resolves this vulnerability.Fixed in 9.0.14 - Upgrade
Upgrade
Palo Alto Networks PAN-OSto a version that resolves this vulnerability.Fixed in 9.1.10 - Upgrade
Upgrade
Palo Alto Networks PAN-OSto a version that resolves this vulnerability.Fixed in 10.0.2 - Upgrade
Upgrade
Palo Alto Networks PAN-OSto a version that resolves this vulnerability.Fixed in 10.1.0
Event History
Frequently Asked Questions
What is CVE-2021-3052?
CVE-2021-3052 is a reflected cross-site scripting (XSS) vulnerability in the Palo Alto Network PAN-OS web interface.
How does CVE-2021-3052 impact Palo Alto Network PAN-OS?
CVE-2021-3052 allows an authenticated network-based attacker to mislead another authenticated PAN-OS administrator to click on a specially crafted link that performs arbitrary actions in the PAN-OS web interface.
Which versions of Palo Alto Network PAN-OS are affected by CVE-2021-3052?
Palo Alto Network PAN-OS versions 8.1.0 to 8.1.20, 9.0.0 to 9.0.14, 9.1.0 to 9.1.10, and 10.0.0 to 10.0.2 are affected by CVE-2021-3052.
What is the severity of CVE-2021-3052?
CVE-2021-3052 has a severity value of 5.4, which is considered high.
How can I fix CVE-2021-3052?
To fix CVE-2021-3052, it is recommended to upgrade to a non-vulnerable version of Palo Alto Network PAN-OS.