Impact
The vulnerability allows an unauthenticated attacker with network access to inject malicious XML content into the Large Scale VPN (LSVPN) subsystem. This XML injection can lead to the disclosure of sensitive internal data or the corruption of LSVPN satellite configuration information, as the software does not properly validate or sanitize XML input. The weakness identified is a classic XML Injection (CWE‑74).
Affected Systems
Affected vendors include Palo Alto Networks PAN‑OS; specific impacted product lines are PAN‑OS software. The vulnerability affects multiple release branches. For the 12.1.x branch, versions from 12.1.2‑h* through 12.1.7‑h2, 12.1.8, or later. For the 11.2.x branch, versions from 11.2.0 through 11.2.10‑h* are affected, requiring an upgrade to 11.2.13 or later. For older 11.1.x, 11.0.x, and10.2.x branches, analogous upgrade paths are recommended as listed in the vendor’s solution, always moving to the latest supported fixed version for the respective branch. PAN‑OS Panorama, Cloud NGFW, and Prisma Access are not impacted.
Risk and Exploitability
The CVSS score of 4.7 places the vulnerability in the Low‑Medium range, reflecting moderate impact and requiring network access. The EPSS score is < 1%, indicating a very low issue is not listed in CISA’s KEV catalog, meaning no confirmed exploitable incidents to date. Even though the flaw permits network‑based XML injection, the lack of public exploitation suggests a lower immediate threat, but a patch should still be applied promptly to mitigate potential future exploitation.
OpenCVE Enrichment