#VU23777 Improper restriction of communication channel to intended endpoints in Palo Alto PAN-OS - CVE-2019-17440
Published: December 20, 2019
Palo Alto PAN-OS
Palo Alto Networks, Inc.
Description
The vulnerability allows a remote attacker to compromise the affected system.
The vulnerability exists due to improper restriction of communications to Log Forwarding Card (LFC) on
PA-7000 Series devices with second-generation Switch Management Card
(SMC). A remote attacker with network access to the LFC can gain perform a spoofing attack and gain root privileges on the device.
Remediation
The vulnerability affects PAn-OS on PA-7080 and PA-7050 devices with an LFC installed and configured.
To resolve the vulnerability, update PAN-OS to version 9.0.5-h3.