Impact
An information disclosure vulnerability in Palo Alto Networks PAN-OS software allows an unauthenticated attacker with network access to the management web interface to obtain web-session tokens after a legitimate user clicks a malicious link. The flaw involves leaking authentication tokens (CWE-524), which could enable an attacker to impersonate that user and potentially perform privileged actions, thereby exposing confidential data or configuration. The reported CVSS score of 1.7 reflects the low impact under normal conditions, as the attacker still requires a targeted user to interact with a malicious link.
Affected Systems
Affected products are Palo Alto Networks PAN-OS across PA-Series, VM-Series, and Panorama (virtual and M-Series) firewalls. Vulnerable versions include PAN-OS 10.2.0 to 10.2.18, 11.1.0 to 11.1.15, 11.2.0 to 11.2.12, and 12.1.2 to 12.1.7. All older unsupported PAN-OS releases are also impacted. Cloud NGFW and Prisma Access are not affected. The summary of fixed releases is PAN-OS 12.1.8 or later, 11.2.13 or later, 11.1.16 or later, or upgrading any 10.2.x branch to 11.1.16, 11.2.13, or 12.1.8 or later.
Risk and Exploitability
Risk is low in terms of score, and the EPSS score is less than 1%, indicating a very low exploitation probability. The vulnerability is not listed in CISA KEV. Based on the description, it is inferred that the attacker must first reach the attack vector is user-targeted phishing combined with network reachability. The impact remains limited to potential session hijacking, but because the attacker needs a valid session token and privileged user interaction, widespread impact is unlikely unless an organization allows management interface exposure to untrusted networks.
OpenCVE Enrichment