Impact
The vulnerability allows an unauthenticated attacker with network access to bypass authentication controls when Cloud Authentication Service is enabled, giving them management access without valid credentials. This could compromise the firewall configuration and the entire network control plane.
Affected Systems
Affected to Palo Alto Networks PAN‑OS firmware on PA‑Series and VM‑Series firewalls, and Panorama appliances. The flaw applies to PAN‑OS versions starting 10.2.0 through 12.1.x, with specific vulnerable ranges listed by the vendor (e.g., 10.2.0‑10.2.7-h*, 10.2.9‑10.2.18-h*, 11.1.0‑11.1.14, 11.2.0‑11.2.11, 12.1.2‑12.1.6). Cloud‑NGFW and Prisma Access are not affected.
Risk and Exploitability
CVSS score of 2.7 indicates low severity; EPSS score is unavailable and the flaw is not in the KEV catalog. The attack most likely occurs over the network when an attacker can reach the management interface with CAS enabled. The risk is higher for management interface exposed to the internet. Mitigation steps including restricting management access to trusted internal IP addresses, disabling CAS, or switching authentication methods effectively eliminate the vulnerability. A correct upgrade to the fixed version provides the most robust protection.
OpenCVE Enrichment