Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-7g39-pmpc-x999

Опубликовано: 13 мая 2026
Источник: github
Github: Не прошло ревью
CVSS4: 5
CVSS3: 8.8

Описание

An arbitrary File Read and Delete Vulnerability in Palo Alto Networks WildFire® WF-500 and WF-500-B appliances enables users to read sensitive information and delete arbitrary files. This vulnerability affects WF-500 and WF-500-B appliances running in the default non-FIPS configuration mode.

The WildFire Appliance (WF-500, WF-500-B) software update is now available to customers that use the WildFire Appliance (WF-500, WF-500-B) for on-premise sandboxing.

Please note that customers using the WildFire Public cloud service are NOT impacted by this vulnerability.

An arbitrary File Read and Delete Vulnerability in Palo Alto Networks WildFire® WF-500 and WF-500-B appliances enables users to read sensitive information and delete arbitrary files. This vulnerability affects WF-500 and WF-500-B appliances running in the default non-FIPS configuration mode.

The WildFire Appliance (WF-500, WF-500-B) software update is now available to customers that use the WildFire Appliance (WF-500, WF-500-B) for on-premise sandboxing.

Please note that customers using the WildFire Public cloud service are NOT impacted by this vulnerability.

EPSS

Процентиль: 26%
0.00336
Низкий

5 Medium

CVSS4

8.8 High

CVSS3

Дефекты

CWE-73

Связанные уязвимости

CVSS3: 8.8
nvd
3 месяца назад

An arbitrary File Read and Delete Vulnerability in Palo Alto Networks WildFire® WF-500 and WF-500-B appliances enables users to read sensitive information and delete arbitrary files. This vulnerability affects WF-500 and WF-500-B appliances running in the default non-FIPS configuration mode. The WildFire Appliance (WF-500, WF-500-B) software update is now available to customers that use the WildFire Appliance (WF-500, WF-500-B) for on-premise sandboxing. Please note that customers using the WildFire Public cloud service are NOT impacted by this vulnerability.

CVSS3: 7.1
fstec
3 месяца назад

Уязвимость микропрограммного обеспечения сетевых устройств WildFire WF-500 и WildFire WF-500-B, связанная с некорректным внешним управлением именем или путем файла, позволяющая нарушителю получить доступ на чтение, изменение и удаление файлов

EPSS

Процентиль: 26%
0.00336
Низкий

5 Medium

CVSS4

8.8 High

CVSS3

Дефекты

CWE-73