Impact
A buffer overflow occurs in the XML parser of PAN‑OS when the management web or dataplane interface receives a specially crafted XML payload, allowing an unauthenticated attacker with network connectivity to cause a denial of service on VM‑Series firewalls or to execute arbitrary code with root privileges on PA‑Series firewalls. The vulnerability is mitigated when management access is limited to trusted internal addresses and when Panorama is also updated.
Affected Systems
The affected products are Palo Alto Networks Cloud NGFW, PAN‑OS, Prisma Access, and Panorama. Vulnerable PAN‑OS releases include 12.2.0‑12.2.2, 12.1.5‑12.1.9, 12.1.2‑12.1.4‑h*, 12.1.0‑12.1.4‑h*, 12.2.0‑12.2.2, 11.2.x, 11.1.x, 10.2.x, and corresponding Panorama and Prisma Access versions. VM‑Series firewalls are impacted for DoS, while PA‑Series firewalls may be impacted for code execution.
Risk and Exploitability
The vulnerability scores a CVSS of 5.2, indicating moderate severity. EPSS is not available, and the CVE is not listed in CISA’s KEV catalog, suggesting that the likelihood of widespread exploitation is currently uncertain. Nonetheless, the payload can be delivered remotely without authentication, making the attack path straightforward for any attacker with network access to the affected interface.
OpenCVE Enrichment