Impact
A stored cross‑site scripting (XSS) flaw in Palo Alto Networks PAN‑OS Web Management Interface enables an authenticated administrator to store or execute a JavaScript payload. The injected script runs in the context of the web interface and can be used to steal session data, manipulate configuration pages, or conduct further malicious activity. This weakness is a classic CWE‑79 input‑validation failure that can lead to unauthorized client‑side code execution.
Affected Systems
The vulnerability affects PAN‑OS releases 11.1.0 through 11.1.16 (upgrade to 11.1.16‑h2 or later), 11.2.0 through 11.2.13 (upgrade to 11.2.13‑h2 or later), and 12.1.2 through 12.1.9 (upgrade to 12.1.10 or later). PAN‑OS 12.2 and all Cloud NGFW and Prisma Access versions are not impacted. The flaw is present on PA‑Series, VM‑Series firewalls and Panorama devices, but not on Cloud‑NGFW or Prisma‑Access deployments.
Risk and Exploitability
The CVSS score is 0.4, indicating low severity, and the EPSS score is not available. The vulnerability is not listed in the CISA KEV catalog. Exploitation requires legitimate administrator credentials and access to the web interface; therefore the risk is primarily to authenticated insiders. No workarounds are available, but a mitigating configuration is to enable Threat ID 510040/510041 with SSL decryption to block malicious payloads on the management interface.
OpenCVE Enrichment