PAN-OS: Local File Deletion Vulnerability

CVE-2023-0004
6.5MEDIUM

Key Information

Status
Pan-os
Prisma Access
Cloud Ngfw
Vendor
CVE Published:
12 April 2023

Badges

👾 Exploit Exists

Summary

A local file deletion vulnerability in Palo Alto Networks PAN-OS software enables an authenticated administrator to delete files from the local file system with elevated privileges. These files can include logs and system components that impact the integrity and availability of PAN-OS software.

Affected Version(s)

PAN-OS < 8.1.24

PAN-OS < 9.0.17

PAN-OS < 9.1.15

CVSS V3.1

Score:
6.5
Severity:
MEDIUM
Confidentiality:
None
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
High
User Interaction:
None
Scope:
Unchanged

Timeline

  • 👾

    Exploit exists.

  • Initial publication

  • Vulnerability published.

  • Vulnerability Reserved.

Collectors

NVD DatabaseMitre Database

Credit

Palo Alto Networks thanks Wim Barthier and Frank Lycops for discovering and reporting this issue.
.