CVE-2023-0005: PAN-OS: Exposure of Sensitive Information Vulnerability
A vulnerability in Palo Alto Networks PAN-OS software enables an authenticated administrator to expose the plaintext values of secrets stored in the device configuration and encrypted API keys.
Affected Software
Remediation
Information
Event History
Frequently Asked Questions
What is CVE-2023-0005?
CVE-2023-0005 is a vulnerability in Palo Alto Networks PAN-OS software that enables an authenticated administrator to expose the plaintext values of secrets stored in the device configuration and encrypted API keys.
How does CVE-2023-0005 impact Palo Alto Networks PAN-OS software?
CVE-2023-0005 allows an authenticated administrator to access and expose sensitive information, such as plaintext secrets and encrypted API keys, stored in the device configuration.
What versions of Palo Alto Networks PAN-OS software are affected by CVE-2023-0005?
Palo Alto Networks PAN-OS software versions 8.1.0 to 8.1.24, 9.0.0 to 9.0.17, 9.1.0 to 9.1.15, 10.0.0 to 10.0.12, 10.1.0 to 10.1.8, and 10.2.0 to 10.2.3 are affected by CVE-2023-0005.
What is the severity of CVE-2023-0005?
CVE-2023-0005 has a severity rating of 4.9, which is considered medium.
How can I mitigate CVE-2023-0005?
To mitigate CVE-2023-0005, it is recommended to upgrade Palo Alto Networks PAN-OS software to a version that is not affected by the vulnerability.