CVE-2023-6791: PAN-OS: Plaintext Disclosure of External System Integration Credentials
A credential disclosure vulnerability in Palo Alto Networks PAN-OS software enables an authenticated read-only administrator to obtain the plaintext credentials of stored external system integrations such as LDAP, SCP, RADIUS, TACACS+, and SNMP from the web interface.
Affected Software
Remediation
Information
Event History
Frequently Asked Questions
What is the severity of CVE-2023-6791?
CVE-2023-6791 is considered a high severity vulnerability due to its potential to expose plaintext credentials of external system integrations.
How do I fix CVE-2023-6791?
To fix CVE-2023-6791, you should update your Palo Alto Networks PAN-OS to the latest version that is not affected.
Who is affected by CVE-2023-6791?
CVE-2023-6791 affects authenticated read-only administrators of Palo Alto Networks PAN-OS versions within specified ranges.
What types of credentials are disclosed in CVE-2023-6791?
CVE-2023-6791 allows exposure of plaintext credentials for external system integrations like LDAP, SCP, RADIUS, TACACS+, and SNMP.
When was CVE-2023-6791 disclosed?
The disclosure date for CVE-2023-6791 is not specified in the provided information.