Improper Authentication in Palo Alto PAN-OS - CVE-2012-6603

 

Improper Authentication in Palo Alto PAN-OS - CVE-2012-6603

Published: August 31, 2013 / Updated: August 10, 2020


Vulnerability identifier: #VU42609
CSH Severity: High
CVSS v4: 9.3 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]
CVE-ID: CVE-2012-6603
CWE-ID: CWE-287
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote non-authenticated attacker to execute arbitrary code.

The web management UI in Palo Alto Networks PAN-OS before 3.1.12, 4.0.x before 4.0.10, and 4.1.x before 4.1.4 allows remote attackers to bypass authentication and obtain administrator privileges via unspecified vectors, aka Ref ID 37034.


Affected software

Palo Alto PAN-OS

How to mitigate CVE-2012-6603

Install update from vendor's website.


External References

Related Security Bulletins