A cross-site scripting (XSS) vulnerability in Palo Alto Networks PAN-OS software enables an authenticated read-write Panorama administrator to push a specially crafted configuration to a PAN-OS node. This enables impersonation of a legitimate PAN-OS administrator who can perform restricted actions on the PAN-OS node after the execution of JavaScript in the legitimate PAN-OS administrator's browser.
2024-11-14T10:15:09.223
2025-01-24T16:06:43.023
Analyzed
CVSSv3.1: 4.8 (MEDIUM)
Type | Vendor | Product | Version/Range | Vulnerable? |
---|---|---|---|---|
Operating System | paloaltonetworks | pan-os | < 10.1.14 | Yes |
Operating System | paloaltonetworks | pan-os | < 10.2.11 | Yes |
Operating System | paloaltonetworks | pan-os | < 11.0.6 | Yes |
Operating System | paloaltonetworks | pan-os | < 11.1.4 | Yes |