#VU86541 Insufficient Session Expiration in Palo Alto PAN-OS


Published: 2024-02-15

Vulnerability identifier: #VU86541

Vulnerability risk: Low

CVSSv3.1: 5.9 [CVSS:3.1/AV:P/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H/E:U/RL:O/RC:C]

CVE-ID: CVE-2024-0008

CWE-ID: CWE-613

Exploitation vector: Local

Exploit availability: No

Vulnerable software:
Palo Alto PAN-OS
Operating systems & Components / Operating system

Vendor: Palo Alto Networks, Inc.

Description

The vulnerability allows a local attacker to gain access to sensitive information.

The vulnerability exists due to insufficient session expiration issue in the management interface. An attacker with physical access can obtain or guess session token and gain unauthorized access to session that belongs to another user.

Mitigation
Install updates from vendor's website.

Vulnerable software versions

Palo Alto PAN-OS: 9.0 - 9.0.17-h1, 9.1 - 9.1.16-h5, 10.0 - 10.0.12, 10.1 - 10.1.10, 10.2 - 10.2.4, 11.0.0 - 11.0.1


External links
http://security.paloaltonetworks.com/CVE-2024-0008


Q & A

Can this vulnerability be exploited remotely?

No. The attacker should have physical access to the system in order to successfully exploit this vulnerability.

Is there known malware, which exploits this vulnerability?

No. We are not aware of malware exploiting this vulnerability.


Latest bulletins with this vulnerability