Information disclosure in PAN-OS 7.1.23 and earlier, PAN-OS 8.0.18 and earlier, PAN-OS 8.1.8-h4 and earlier, and PAN-OS 9.0.2 and earlier may allow for an authenticated user with read-only privileges to extract the API key of the device and/or the username/password from the XML API (in PAN-OS) and possibly escalate privileges granted to them.
Advisories
Source ID Title
EUVD EUVD EUVD-2019-10132 Information disclosure in PAN-OS 7.1.23 and earlier, PAN-OS 8.0.18 and earlier, PAN-OS 8.1.8-h4 and earlier, and PAN-OS 9.0.2 and earlier may allow for an authenticated user with read-only privileges to extract the API key of the device and/or the username/password from the XML API (in PAN-OS) and possibly escalate privileges granted to them.
Fixes

Solution

No solution given by the vendor.


Workaround

No workaround given by the vendor.

History

No history.

Projects

Sign in to view the affected projects.

cve-icon MITRE

Status: PUBLISHED

Assigner: palo_alto

Published:

Updated: 2024-08-04T18:20:28.319Z

Reserved: 2018-12-06T00:00:00

Link: CVE-2019-1575

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Modified

Published: 2019-07-16T14:15:12.060

Modified: 2024-11-21T04:36:50.560

Link: CVE-2019-1575

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

No data.

Weaknesses