CVE-2024-8688
PAN-OS: Arbitrary File Read Vulnerability in the Command Line Interface (CLI)
Severity
Medium 6.7
CVSS 4.0
Exploited
Not listed
EPSS
0.002
14.4th percentile
Discovered by
Third party
Published by the vendor
Published
Sep 11, 2024
Assigned by palo_alto
Description
An improper neutralization of matching symbols vulnerability in the Palo Alto Networks PAN-OS command line interface (CLI) enables authenticated administrators (including read-only administrators) with access to the CLI to to read arbitrary files on the firewall.
Weakness: CWE-155
Affected products
| Vendor | Product | Category | Matched by |
|---|---|---|---|
| Palo Alto Networks | Cloud NGFW | Firewall / NGFW | cna-assigner |
| Palo Alto Networks | PAN-OS | Firewall / NGFW | cna-assigner |
| Palo Alto Networks | Prisma Access | SASE / SSE / Secure Web | cna-assigner |
Vendor-reported affected versions (3)
- Palo Alto Networks · PAN-OS
- Palo Alto Networks · Cloud NGFW
- Palo Alto Networks · Prisma Access
Credit
Matei "Mal" Badanoiu of Deloitte
Vendor remediation
This issue is fixed in PAN-OS 9.1.15, PAN-OS 10.0.10, PAN-OS 10.1.1, and all later PAN-OS versions.