Authenticated File Read Vulnerability in Palo Alto Networks PAN-OS Management Interface
A vulnerability exists in Palo Alto Networks PAN-OS software that allows an authenticated admin using the CLI to read arbitrary files. To exploit this issue, an attacker must first gain network access to the management interface through web, SSH, console, or telnet and successfully authenticate. The vulnerability can be mitigated by limiting management interface access to trusted users and internal IP addresses, following Palo Alto Networks' recommended critical deployment guidelines. Cloud NGFW and Prisma Access are not impacted by this security issue.
Vulnerable Product | Search on Vulmon | Subscribe to Product |
---|---|---|
paloaltonetworks pan-os 11.2.2 |
||
paloaltonetworks pan-os 11.2.1 |
||
paloaltonetworks pan-os 11.2.0 |
||
paloaltonetworks pan-os 11.1.4 |
||
paloaltonetworks pan-os 11.1.3 |
||
paloaltonetworks pan-os 11.1.2 |
||
paloaltonetworks pan-os 11.1.1 |
||
paloaltonetworks pan-os 11.1.0 |
||
paloaltonetworks pan-os 11.0.5 |
||
paloaltonetworks pan-os 11.0.4 |
||
paloaltonetworks pan-os 11.0.3 |
||
paloaltonetworks pan-os 11.0.2 |
||
paloaltonetworks pan-os 11.0.1 |
||
paloaltonetworks pan-os 11.0.0 |
||
paloaltonetworks pan-os 10.2.10 |
||
paloaltonetworks pan-os 10.2.9 |
||
paloaltonetworks pan-os 10.2.8 |
||
paloaltonetworks pan-os 10.2.7 |
||
paloaltonetworks pan-os 10.2.6 |
||
paloaltonetworks pan-os 10.2.5 |
||
paloaltonetworks pan-os 10.2.4 |
||
paloaltonetworks pan-os 10.2.3 |
||
paloaltonetworks pan-os 10.2.2 |
||
paloaltonetworks pan-os 10.2.1 |
||
paloaltonetworks pan-os 10.2.0 |
||
paloaltonetworks pan-os 10.1.14 |
||
paloaltonetworks pan-os 10.1.13 |
||
paloaltonetworks pan-os 10.1.12 |
||
paloaltonetworks pan-os 10.1.11 |
||
paloaltonetworks pan-os 10.1.10 |
||
paloaltonetworks pan-os 10.1.9 |
||
paloaltonetworks pan-os 10.1.8 |
||
paloaltonetworks pan-os 10.1.7 |
||
paloaltonetworks pan-os 10.1.6 |
||
paloaltonetworks pan-os 10.1.5 |
||
paloaltonetworks pan-os 10.1.4 |
||
paloaltonetworks pan-os 10.1.3 |
||
paloaltonetworks pan-os 10.1.2 |
||
paloaltonetworks pan-os 10.1.1 |
||
paloaltonetworks pan-os 10.1.0 |
||
palo alto networks pan-os |
||
palo alto networks cloud ngfw |
||
palo alto networks prisma access |