A cross-site scripting (XSS) vulnerability in Palo Alto Networks PAN-OS software enables a malicious authenticated read-write administrator to store a JavaScript payload using the web interface on Panorama appliances. This enables the impersonation of another authenticated administrator.
2024-02-14T18:15:47.110
2024-12-17T18:09:56.970
Analyzed
CVSSv3.1: 6.8 (MEDIUM)
| Type | Vendor | Product | Version/Range | Vulnerable? |
|---|---|---|---|---|
| Operating System | paloaltonetworks | pan-os | < 8.1.24 | Yes |
| Operating System | paloaltonetworks | pan-os | < 9.0.17 | Yes |
| Operating System | paloaltonetworks | pan-os | < 9.1.16 | Yes |
| Operating System | paloaltonetworks | pan-os | < 10.0.11 | Yes |
| Operating System | paloaltonetworks | pan-os | < 10.1.6 | Yes |
| Operating System | paloaltonetworks | pan-os | 8.1.24 | Yes |
| Hardware | paloaltonetworks | panorama_m-200 | - | No |
| Hardware | paloaltonetworks | panorama_m-500 | - | No |
| Hardware | paloaltonetworks | panorama_m-600 | - | No |