#VU39099 Information Exposure Through an Error Message in Palo Alto PAN-OS - CVE-2017-7945 

 

#VU39099 Information Exposure Through an Error Message in Palo Alto PAN-OS - CVE-2017-7945

Published: April 29, 2017 / Updated: August 8, 2020


Vulnerability identifier: #VU39099
Vulnerability risk: Low
CVSSv4.0: CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N/E:U/U:Clear
CVE-ID: CVE-2017-7945
CWE-ID: CWE-209
Exploitation vector: Remote access
Exploit availability: No public exploit available
Vulnerable software:
Palo Alto PAN-OS
Software vendor:
Palo Alto Networks, Inc.

Description

The vulnerability allows a remote non-authenticated attacker to execute arbitrary code.

The GlobalProtect external interface in Palo Alto Networks PAN-OS before 6.1.17, 7.x before 7.0.15, 7.1.x before 7.1.9, and 8.x before 8.0.2 provides different error messages for failed login attempts depending on whether the username exists, which allows remote attackers to enumerate account names and conduct brute-force attacks via a series of requests, aka PAN-SA-2017-0014 and PAN-72769.


Remediation

Install update from vendor's website.

External links