A cross-site scripting (XSS) vulnerability in Palo Alto Networks PAN-OS software enables a malicious authenticated read-write administrator to store a JavaScript payload using the web interface on Panorama appliances. This enables the impersonation of another authenticated administrator.
2024-02-14T18:15:47.110
2024-12-17T18:09:56.970
Analyzed
CVSSv3.1: 6.8 (MEDIUM)
Type | Vendor | Product | Version/Range | Vulnerable? |
---|---|---|---|---|
Operating System | paloaltonetworks | pan-os | < 8.1.24 | Yes |
Operating System | paloaltonetworks | pan-os | < 9.0.17 | Yes |
Operating System | paloaltonetworks | pan-os | < 9.1.16 | Yes |
Operating System | paloaltonetworks | pan-os | < 10.0.11 | Yes |
Operating System | paloaltonetworks | pan-os | < 10.1.6 | Yes |
Operating System | paloaltonetworks | pan-os | 8.1.24 | Yes |
Hardware | paloaltonetworks | panorama_m-200 | - | No |
Hardware | paloaltonetworks | panorama_m-500 | - | No |
Hardware | paloaltonetworks | panorama_m-600 | - | No |