PAN-OS: Exposure of Sensitive Information Vulnerability

CVE-2023-0005
4.1MEDIUM

Key Information

Status
Pan-os
Prisma Access
Cloud Ngfw
Vendor
CVE Published:
12 April 2023

Badges

👾 Exploit Exists

Summary

A vulnerability in Palo Alto Networks PAN-OS software enables an authenticated administrator to expose the plaintext values of secrets stored in the device configuration and encrypted API keys.

Affected Version(s)

PAN-OS >= 11.0

PAN-OS < 10.2.3

PAN-OS < 10.1.8

CVSS V3.1

Score:
4.1
Severity:
MEDIUM
Confidentiality:
High
Integrity:
None
Availability:
None
Attack Vector:
Local
Attack Complexity:
High
Privileges Required:
High
User Interaction:
None
Scope:
Unchanged

Timeline

  • 👾

    Exploit exists.

  • Risk change from: 4.9 to: 4.1 - (MEDIUM)

  • Initial publication

  • Vulnerability published.

  • Vulnerability Reserved.

Collectors

NVD DatabaseMitre Database

Credit

Palo Alto Networks thanks the security researcher rqu for discovering and reporting this issue.
.