Authenticated File Deletion Vulnerability in Palo Alto Networks PAN-OS Management Interface
An authenticated file deletion vulnerability exists in Palo Alto Networks PAN-OS® software that allows an authenticated attacker with management web interface access to delete specific files as the "nobody" user. The vulnerable files include limited logs and configuration files, but system files remain protected. To exploit this issue, the attacker requires network access to the management web interface. Palo Alto Networks recommends significantly reducing risk by restricting management web interface access to trusted internal IP addresses, as outlined in their critical deployment guidelines. While this vulnerability affects Cloud NGFW, it does not impact Prisma® Access software.
Vulnerable Product | Search on Vulmon | Subscribe to Product |
---|---|---|
paloaltonetworks pan-os 11.2.0 |
||
paloaltonetworks pan-os 11.1.4 |
||
paloaltonetworks pan-os 11.1.3 |
||
paloaltonetworks pan-os 11.1.2 |
||
paloaltonetworks pan-os 11.1.1 |
||
paloaltonetworks pan-os 11.1.0 |
||
paloaltonetworks pan-os 11.0.5 |
||
paloaltonetworks pan-os 11.0.4 |
||
paloaltonetworks pan-os 11.0.3 |
||
paloaltonetworks pan-os 11.0.2 |
||
paloaltonetworks pan-os 11.0.1 |
||
paloaltonetworks pan-os 11.0.0 |
||
paloaltonetworks pan-os 10.2.9 |
||
paloaltonetworks pan-os 10.2.8 |
||
paloaltonetworks pan-os 10.2.7 |
||
paloaltonetworks pan-os 10.2.6 |
||
paloaltonetworks pan-os 10.2.5 |
||
paloaltonetworks pan-os 10.2.4 |
||
paloaltonetworks pan-os 10.2.3 |
||
paloaltonetworks pan-os 10.2.2 |
||
paloaltonetworks pan-os 10.2.1 |
||
paloaltonetworks pan-os 10.2.0 |
||
paloaltonetworks pan-os 10.1.14 |
||
paloaltonetworks pan-os 10.1.13 |
||
paloaltonetworks pan-os 10.1.12 |
||
paloaltonetworks pan-os 10.1.11 |
||
paloaltonetworks pan-os 10.1.10 |
||
paloaltonetworks pan-os 10.1.9 |
||
paloaltonetworks pan-os 10.1.8 |
||
paloaltonetworks pan-os 10.1.7 |
||
paloaltonetworks pan-os 10.1.6 |
||
paloaltonetworks pan-os 10.1.5 |
||
paloaltonetworks pan-os 10.1.4 |
||
paloaltonetworks pan-os 10.1.3 |
||
paloaltonetworks pan-os 10.1.2 |
||
paloaltonetworks pan-os 10.1.1 |
||
paloaltonetworks pan-os 10.1.0 |
||
palo alto networks cloud ngfw |
||
palo alto networks pan-os |
||
palo alto networks prisma access |