Back

HIGH

Missing XML Validation in PAN-OS Web Interface

Published Feb 12, 2020

Description

Missing XML validation vulnerability in the PAN-OS web interface on Palo Alto Networks PAN-OS software allows authenticated users to inject arbitrary XML that results in privilege escalation. This issue affects PAN-OS 8.1 versions earlier than PAN-OS 8.1.12 and PAN-OS 9.0 versions earlier than PAN-OS 9.0.6. This issue does not affect PAN-OS 7.1, PAN-OS 8.0, or PAN-OS 9.1 or later versions.

Affected products

Remediation

Vendor solution

This issue is fixed in PAN-OS 8.1.12, PAN-OS 9.0.6, and all later versions.

Weaknesses (2)

References (2)

Change history (0)

No recorded changes yet.

Sources

CVE.org / MITRE

Status PUBLISHED
Assigner palo_alto
Published Feb 12, 2020
Updated Sep 16, 2024
Reserved Dec 4, 2019

CISA Vulnrichment

No data

NVD

Status Modified
Modified Jun 17, 2026

Red Hat

No data

ENISA EUVD

Assigner palo_alto
Published Feb 12, 2020
Updated Sep 16, 2024

GitHub

No data