Information Exposure Through an Error Message in Palo Alto PAN-OS - CVE-2017-7945

 

Information Exposure Through an Error Message in Palo Alto PAN-OS - CVE-2017-7945

Published: April 29, 2017 / Updated: August 8, 2020


Vulnerability identifier: #VU39099
CSH Severity: Low
CVSS v4.0: CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N/E:U/U:Clear
CVE-ID: CVE-2017-7945
CWE-ID: CWE-209
Exploitation vector: Remote access
Exploit availability: No public exploit available
Vendor: Palo Alto Networks, Inc.
Affected software:
Palo Alto PAN-OS

Detailed vulnerability description

The vulnerability allows a remote non-authenticated attacker to execute arbitrary code.

The GlobalProtect external interface in Palo Alto Networks PAN-OS before 6.1.17, 7.x before 7.0.15, 7.1.x before 7.1.9, and 8.x before 8.0.2 provides different error messages for failed login attempts depending on whether the username exists, which allows remote attackers to enumerate account names and conduct brute-force attacks via a series of requests, aka PAN-SA-2017-0014 and PAN-72769.


How to mitigate CVE-2017-7945

Install update from vendor's website.

Sources