PT-2017-17860 · Palo Alto Networks · Pan-Os

Christophe Schleypen

·

Published

2017-04-28

·

Updated

2020-02-17

·

CVE-2017-7644

CVSS v3.1

6.5

Medium

VectorAV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N
Name of the Vulnerable Software and Affected Versions Palo Alto Networks PAN-OS versions 6.1.16 and earlier Palo Alto Networks PAN-OS versions 7.0.14 and earlier Palo Alto Networks PAN-OS versions 7.1.8 and earlier
Description The Management Web Interface in Palo Alto Networks PAN-OS contains an issue that allows remote authenticated users to obtain sensitive information due to incorrect permission validation. This issue can be exploited by an attacker who is authenticated.
Recommendations For versions 6.1.16 and earlier, update to version 6.1.17 or later. For versions 7.0.14 and earlier, update to version 7.0.15 or later. For versions 7.1.8 and earlier, update to version 7.1.9 or later.

Fix

Information Disclosure

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2017-7644

Affected Products

Pan-Os