Information disclosure in Palo Alto PAN-OS - #VU781

 

Information disclosure in Palo Alto PAN-OS - #VU781

Published: October 6, 2016 / Updated: October 6, 2016


Vulnerability identifier: #VU781
CSH Severity: Low
CVSS v4: 6.9 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N]
CVE-ID: N/A
CWE-ID: CWE-200
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote user to obtain potentially sensitive data on the target system.
The weakness is caused by improper access control. Connecting to the GlobalProtect Portal web interface attackers can determine the PAN-OS version number.
Successful exploitation of the vulnerability may result in disclosure of system information on the vulnerable system.

Affected software

Palo Alto PAN-OS

Remediation

Update to version 7.0.10 or 7.1.5.


External References

Related Security Bulletins