Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-9whw-75p3-6rp9

Опубликовано: 09 июл. 2026
Источник: github
Github: Не прошло ревью
CVSS4: 4.7
CVSS3: 9.9

Описание

An XML injection vulnerability in the Large Scale VPN (LSVPN) functionality of Palo Alto Networks PAN-OS® software enables an unauthenticated attacker with network access to inject malicious XML content, potentially leading to information disclosure or corruption of internal LSVPN satellite data.

Panorama, Cloud NGFW, and Prisma® Access are not impacted by this vulnerability.

An XML injection vulnerability in the Large Scale VPN (LSVPN) functionality of Palo Alto Networks PAN-OS® software enables an unauthenticated attacker with network access to inject malicious XML content, potentially leading to information disclosure or corruption of internal LSVPN satellite data.

Panorama, Cloud NGFW, and Prisma® Access are not impacted by this vulnerability.

EPSS

Процентиль: 19%
0.0027
Низкий

4.7 Medium

CVSS4

9.9 Critical

CVSS3

Дефекты

CWE-74

Связанные уязвимости

CVSS3: 9.9
nvd
24 дня назад

An XML injection vulnerability in the Large Scale VPN (LSVPN) functionality of Palo Alto Networks PAN-OS® software enables an unauthenticated attacker with network access to inject malicious XML content, potentially leading to information disclosure or corruption of internal LSVPN satellite data. Panorama, Cloud NGFW, and Prisma® Access are not impacted by this vulnerability.

CVSS3: 7.2
fstec
26 дней назад

Уязвимость модуля Large Scale VPN (LSVPN) операционной системы PAN-OS, позволяющая нарушителю раскрыть защищаемую информацию

EPSS

Процентиль: 19%
0.0027
Низкий

4.7 Medium

CVSS4

9.9 Critical

CVSS3

Дефекты

CWE-74