CVE-2023-6790: PAN-OS: DOM-Based Cross-Site Scripting (XSS) Vulnerability in the Web Interface
A DOM-Based cross-site scripting (XSS) vulnerability in Palo Alto Networks PAN-OS software enables a remote attacker to execute a JavaScript payload in the context of an administrator’s browser when they view a specifically crafted link to the PAN-OS web interface.
Affected Software
Remediation
Information
Event History
Frequently Asked Questions
What is the severity of CVE-2023-6790?
CVE-2023-6790 is a high severity DOM-based cross-site scripting (XSS) vulnerability in Palo Alto Networks PAN-OS software.
How do I fix CVE-2023-6790?
To fix CVE-2023-6790, update the PAN-OS software to versions 8.1.26, 9.0.18, 9.1.17, 10.0.13, 10.1.10, 10.2.5, or 11.0.1, as applicable.
Which versions of PAN-OS are affected by CVE-2023-6790?
CVE-2023-6790 affects Palo Alto Networks PAN-OS versions 8.1.0 to 8.1.25, 9.0.0 to 9.0.17, 9.1.0 to 9.1.16, 10.0.0 to 10.0.12, 10.1.0 to 10.1.9, 10.2.0 to 10.2.4, and 11.0.0.
What type of attack does CVE-2023-6790 enable?
CVE-2023-6790 enables a remote attacker to execute a JavaScript payload in an administrator's browser via a specially crafted link.
Who is primarily affected by CVE-2023-6790?
Administrators using the affected versions of Palo Alto Networks PAN-OS software are primarily at risk from CVE-2023-6790.