Use of Password Hash With Insufficient Computational Effort in Palo Alto PAN-OS - CVE-2022-0022
Published: March 9, 2022
Palo Alto PAN-OS
Palo Alto Networks, Inc.
Description
The vulnerability allows a local user to decrypt credentials.
The vulnerability exists due to software does not use the sufficient level of computational effort when creating password hashes for local user account. A local privileged user can crack passwords.
The vulnerability affects only to PAN-OS firewalls and Panorama appliances running in normal (non-FIPS-CC) operational mode.