#VU84409 Unprotected storage of credentials in Palo Alto PAN-OS - CVE-2023-6791
Published: December 13, 2023
Palo Alto PAN-OS
Palo Alto Networks, Inc.
Description
The vulnerability allows a remote user to gain access to other users' credentials.
The vulnerability exists due to application stores external system integration credentials in plain text. A remote read-only administrator can obtain the plaintext credentials of stored external system integrations such as LDAP, SCP, RADIUS, TACACS+, and SNMP from the web interface.