CVE-2024-0007
PAN-OS: Stored Cross-Site Scripting (XSS) Vulnerability in the Panorama Web Interface
Severity
Medium 6.8
CVSS 3.1
Exploited
Not listed
EPSS
0.004
32.3th percentile
Discovered by
Third party
Published by the vendor
Published
Feb 14, 2024
Assigned by palo_alto
Description
A cross-site scripting (XSS) vulnerability in Palo Alto Networks PAN-OS software enables a malicious authenticated read-write administrator to store a JavaScript payload using the web interface on Panorama appliances. This enables the impersonation of another authenticated administrator.
Weakness: CWE-79
Affected products
| Vendor | Product | Category | Matched by |
|---|---|---|---|
| Palo Alto Networks | Cloud NGFW | Firewall / NGFW | cna-assigner |
| Palo Alto Networks | PAN-OS | Firewall / NGFW | cna-assigner |
| Palo Alto Networks | Prisma Access | SASE / SSE / Secure Web | cna-assigner |
Vendor-reported affected versions (3)
- Palo Alto Networks · PAN-OS
- Palo Alto Networks · Prisma Access
- Palo Alto Networks · Cloud NGFW
Credit
Palo Alto Networks thanks an external reporter for discovering and reporting this issue.
Vendor remediation
This issue is fixed on Panorama in PAN-OS 8.1.24-h1, PAN-OS 9.0.17, PAN-OS 9.1.16, PAN-OS 10.0.11, PAN-OS 10.1.6, and all later PAN-OS versions.