Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-3vmp-6pgh-4q54

Опубликовано: 09 июл. 2026
Источник: github
Github: Не прошло ревью
CVSS4: 4.7
CVSS3: 4.9

Описание

A server-side request forgery (SSRF) vulnerability in Palo Alto Networks PAN-OS software enables an authenticated administrator with network access to the management web interface to make unauthorized requests from the firewall to internal services.

The security risk posed by this issue is minimized when the management interface is restricted to only trusted internal IP addresses according to our recommended  best practice deployment guidelines https://live.paloaltonetworks.com/t5/community-blogs/tips-amp-tricks-how-to-secure-the-management-access-of-your-palo/ba-p/464431

Panorama, Cloud NGFW, and Prisma® Access are not impacted by this vulnerability.

A server-side request forgery (SSRF) vulnerability in Palo Alto Networks PAN-OS software enables an authenticated administrator with network access to the management web interface to make unauthorized requests from the firewall to internal services.

The security risk posed by this issue is minimized when the management interface is restricted to only trusted internal IP addresses according to our recommended  best practice deployment guidelines https://live.paloaltonetworks.com/t5/community-blogs/tips-amp-tricks-how-to-secure-the-management-access-of-your-palo/ba-p/464431

Panorama, Cloud NGFW, and Prisma® Access are not impacted by this vulnerability.

EPSS

Процентиль: 13%
0.0022
Низкий

4.7 Medium

CVSS4

4.9 Medium

CVSS3

Дефекты

CWE-918

Связанные уязвимости

CVSS3: 4.9
nvd
24 дня назад

A server-side request forgery (SSRF) vulnerability in Palo Alto Networks PAN-OS software enables an authenticated administrator with network access to the management web interface to make unauthorized requests from the firewall to internal services. The security risk posed by this issue is minimized when the management interface is restricted to only trusted internal IP addresses according to our recommended  best practice deployment guidelines https://live.paloaltonetworks.com/t5/community-blogs/tips-amp-tricks-how-to-secure-the-management-access-of-your-palo/ba-p/464431 .  Panorama, Cloud NGFW, and Prisma® Access are not impacted by this vulnerability.

CVSS3: 5.5
fstec
26 дней назад

Уязвимость веб-интерфейса управления операционной системы PAN-OS, позволяющая нарушителю обойти существующие механизмы безопасности

EPSS

Процентиль: 13%
0.0022
Низкий

4.7 Medium

CVSS4

4.9 Medium

CVSS3

Дефекты

CWE-918