Impact
Multiple cross‑site scripting vulnerabilities (CWE‑79) exist in PAN‑OS components, including the User‑ID Authentication Portal (aka Captive Portal) and the GlobalProtect gateway/portal, allowing an unauthenticated user to store or execute malicious JavaScript payloads. The vulnerability can compromise the integrity of web interfaces and potentially enable an attacker to run arbitrary scripts in the victim’s browser context, leading to credential theft or session hijacking. The impact is confined to the web interfaces exposed by the firewall and the clientless VPN portals.
Affected Systems
The vulnerability affects PAN‑OS running on PA‑Series and VM‑Series firewalls as well as Panorama (virtual and M‑Series). It also affects Prisma Access, where versions ranging from 12.112.1.2 through 12.1.7-h*, 11.211.2.0 through 11.2*, and 10.210.2.0 through 10.2* are impacted; cloud‑based NGFWs are not affected.
Risk and Exploitability
The CVSS score is 0.4 and the EPSS score indicates an exploitation probability of less than 1%. The vulnerability is not in the CISA KEV catalog. The risk is low in line with the low CVSS score, but exploitation is possible if the interfaces are reachable from an untrusted network. Restricting access to trusted internal IP addresses reduces the likelihood of exploitation.
OpenCVE Enrichment