PT-2017-17860 · Palo Alto Networks · Pan-Os
Christophe Schleypen
·
Publicado
2017-04-28
·
Atualizado
2020-02-17
·
CVE-2017-7644
CVSS v3.1
6.5
Média
| Vetor | AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N |
Name of the Vulnerable Software and Affected Versions
Palo Alto Networks PAN-OS versions 6.1.16 and earlier
Palo Alto Networks PAN-OS versions 7.0.14 and earlier
Palo Alto Networks PAN-OS versions 7.1.8 and earlier
Description
The Management Web Interface in Palo Alto Networks PAN-OS contains an issue that allows remote authenticated users to obtain sensitive information due to incorrect permission validation. This issue can be exploited by an attacker who is authenticated.
Recommendations
For versions 6.1.16 and earlier, update to version 6.1.17 or later.
For versions 7.0.14 and earlier, update to version 7.0.15 or later.
For versions 7.1.8 and earlier, update to version 7.1.9 or later.
Correção
Information Disclosure
Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾
Enumeração de Fraquezas
Identificadores relacionados
Produtos afetados
Pan-Os