7.5
CVSSv2

CVE-2017-9458

Published: 07/09/2017 Updated: 17/02/2020
CVSS v2 Base Score: 7.5 | Impact Score: 6.4 | Exploitability Score: 10
CVSS v3 Base Score: 9.8 | Impact Score: 5.9 | Exploitability Score: 3.9
VMScore: 668
Vector: AV:N/AC:L/Au:N/C:P/I:P/A:P

Vulnerability Summary

XML external entity (XXE) vulnerability in the GlobalProtect internal and external gateway interface in Palo Alto Networks PAN-OS prior to 6.1.18, 7.0.x prior to 7.0.17, 7.1.x prior to 7.1.12, and 8.0.x prior to 8.0.3 allows remote malicious users to obtain sensitive information, cause a denial of service, or conduct server-side request forgery (SSRF) attacks via unspecified vectors.

Vulnerable Product Search on Vulmon Subscribe to Product

paloaltonetworks pan-os 7.0.4

paloaltonetworks pan-os 7.0.5

paloaltonetworks pan-os 7.0.6

paloaltonetworks pan-os 7.0.7

paloaltonetworks pan-os 7.1.8

paloaltonetworks pan-os 7.1.9

paloaltonetworks pan-os 7.1.10

paloaltonetworks pan-os 7.1.11

paloaltonetworks pan-os 7.0.1

paloaltonetworks pan-os 7.0.3

paloaltonetworks pan-os 7.0.8

paloaltonetworks pan-os 7.0.10

paloaltonetworks pan-os 7.1.4

paloaltonetworks pan-os 7.1.6

paloaltonetworks pan-os 8.0.1

paloaltonetworks pan-os

paloaltonetworks pan-os 7.0.12

paloaltonetworks pan-os 7.1.0

paloaltonetworks pan-os 7.1.1

paloaltonetworks pan-os 7.1.2

paloaltonetworks pan-os 7.1.3

paloaltonetworks pan-os 7.0.0

paloaltonetworks pan-os 7.0.2

paloaltonetworks pan-os 7.0.9

paloaltonetworks pan-os 7.0.11

paloaltonetworks pan-os 7.1.5

paloaltonetworks pan-os 7.1.7

paloaltonetworks pan-os 8.0.0

paloaltonetworks pan-os 8.0.2