PT-2017-17860 · Palo Alto Networks · Pan-Os
Christophe Schleypen
·
Published
2017-04-28
·
Updated
2020-02-17
·
CVE-2017-7644
CVSS v3.1
6.5
Medium
| Vector | AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N |
Name of the Vulnerable Software and Affected Versions
Palo Alto Networks PAN-OS versions 6.1.16 and earlier
Palo Alto Networks PAN-OS versions 7.0.14 and earlier
Palo Alto Networks PAN-OS versions 7.1.8 and earlier
Description
The Management Web Interface in Palo Alto Networks PAN-OS contains an issue that allows remote authenticated users to obtain sensitive information due to incorrect permission validation. This issue can be exploited by an attacker who is authenticated.
Recommendations
For versions 6.1.16 and earlier, update to version 6.1.17 or later.
For versions 7.0.14 and earlier, update to version 7.0.15 or later.
For versions 7.1.8 and earlier, update to version 7.1.9 or later.
Fix
Information Disclosure
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Pan-Os