First published: Wed Apr 10 2024(Updated: )
An incorrect string comparison vulnerability in Palo Alto Networks PAN-OS software prevents Predefined Decryption Exclusions from functioning as intended. This can cause traffic destined for domains that are not specified in Predefined Decryption Exclusions to be unintentionally excluded from decryption.
Credit: psirt@paloaltonetworks.com
Affected Software | Affected Version | How to fix |
---|---|---|
Palo Alto Networks PAN-OS | ||
Paloaltonetworks Pan-os | >=9.0.0<9.0.16 | |
Paloaltonetworks Pan-os | >=9.1.0<9.1.17 | |
Paloaltonetworks Pan-os | >=10.0.0<10.0.13 | |
Paloaltonetworks Pan-os | >=10.1.0<=10.1.8 | |
Paloaltonetworks Pan-os | >=10.2.0<10.2.4 | |
Paloaltonetworks Pan-os | >=11.0.0<11.0.1 | |
Paloaltonetworks Pan-os | =9.0.17 | |
Paloaltonetworks Pan-os | =9.0.17-h1 | |
Paloaltonetworks Pan-os | =10.1.9 | |
Paloaltonetworks Pan-os | =10.1.9-h1 | |
Paloaltonetworks Pan-os | =10.2.4 | |
Paloaltonetworks Pan-os | =11.0.1 |
This issue is fixed in 9.0.17-h2, 9.0.18, 9.1.17, 10.0.13, 10.1.9-h3, 10.1.10, 10.2.4-h2, 10.2.5, 11.0.1-h2, 11.0.2, 11.1.0 and all later PAN-OS versions.
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.