Unauthorized Access Vulnerability in PAN-OS Software
CVE-2024-0008
8.8HIGH
Summary
The management interface of Palo Alto Networks PAN-OS software is vulnerable due to a session management flaw that permits web sessions to remain active indefinitely in specific situations. This oversight can lead to unauthorized access, potentially allowing attackers to exploit user privileges. Organizations using affected versions of PAN-OS should assess their exposure and implement appropriate security measures to mitigate this risk to their network security.
Affected Version(s)
PAN-OS 9.0 < 9.0.17-h2
PAN-OS 9.0 < 9.0.18
PAN-OS 9.1 < 9.1.17
References
CVSS V3.1
Score:
8.8
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
Required
Scope:
Unchanged
Timeline
- 👾
Exploit known to exist
Vulnerability published
Vulnerability Reserved
Credit
Palo Alto Networks thanks Brian Yaklin for discovering and reporting this issue.