PAN-OS: DOM-Based Cross-Site Scripting (XSS) Vulnerability in the Web Interface
Published Dec 13, 2023
8.8
HIGHCVSS 3.1
EPSS 0.66%
Description
A DOM-Based cross-site scripting (XSS) vulnerability in Palo Alto Networks PAN-OS software enables a remote attacker to execute a JavaScript payload in the context of an administrator’s browser when they view a specifically crafted link to the PAN-OS web interface.
Affected products
-
Affected
- ≥ 10.0, < 10.0.12
- ≥ 10.1, < 10.1.9
- ≥ 10.2, < 10.2.4
- ≥ 11.0, < 11.0.1
- ≥ 8.1, < 8.1.25
- ≥ 9.0, < 9.0.17
- ≥ 9.1, < 9.1.16
Unaffected
- ≥ 11.1, < All
Default status is the baseline for the product. Each version can override it (patched versions can be marked unaffected).
| Vendor | Product | Default status | Versions |
|---|---|---|---|
| Palo Alto Networks | Pan-OS | unaffected | Affected
Unaffected
|
- ≥ 8.1.0 · < 8.1.25
- ≥ 9.0.0 · < 9.0.17
- ≥ 9.1.0 · < 9.1.16
- ≥ 10.0.0 · < 10.0.12
- ≥ 10.1.0 · < 10.1.9
- ≥ 10.2.0 · < 10.2.4
- 11.0.0
No data.
No Red Hat product state for this CVE.
No package ranges for this CVE.
Remediation
Vendor solution
This issue is fixed in PAN-OS 8.1.25, PAN-OS 9.0.17, PAN-OS 9.1.16, PAN-OS 10.0.12, PAN-OS 10.1.9, PAN-OS 10.2.4, PAN-OS 11.0.1, and all later PAN-OS versions.
References (2)
- https://euvd.enisa.europa.eu/vulnerability/EUVD-2023-59001 Advisory
- https://security.paloaltonetworks.com/CVE-2023-6790 Vendor Advisory
| Link | Providers | Tags |
|---|---|---|
| https://euvd.enisa.europa.eu/vulnerability/EUVD-2023-59001 | Advisory | |
| https://security.paloaltonetworks.com/CVE-2023-6790 | Vendor Advisory |
Change history (0)
No recorded changes yet.
CVE.org / MITRE
CISA Vulnrichment
No data
Red Hat
No data
GitHub
No data