Impact
An SSRF flaw in the PAN‑OS management web interface permits an authenticated administrator who has network access to that interface to instruct the device to fetch arbitrary URLs. This can lead to exposure of internal services, data exfiltration, or lateral movement within the protected network, and is classified as CWE‑918.
Affected Systems
The vulnerability is present in Palo Alto Networks PAN‑OS appliances running firmware versions 10.2.0‑10.2.18‑h*, 11.1.0‑11.1.15, and 12.1.0‑12.1.7‑h*, except that Panorama, Cloud NGFW, and Prisma® Access are not affected.
Risk and Exploitability
The CVSS score of 4.4 and an EPSS of less than 1 % indicate moderate severity and a very low likelihood of exploitation. Because the exploit requires valid administrative credentials and network reachability to the management interface, the attack vector is effectively internal or privileged remote. The risk is mitigated by restricting management access to trusted internal IPs, disabling the service, or applying the vendor‑issued patch. The vulnerability is not listed in CISA’s KEV catalog.
OpenCVE Enrichment