Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-p4fj-c8rg-ggm6

Опубликовано: 09 окт. 2025
Источник: github
Github: Не прошло ревью
CVSS4: 4.8
CVSS3: 2.7

Описание

An information disclosure vulnerability in Palo Alto Networks PAN-OS® software enables an authenticated administrator to view session tokens of users authenticated to the firewall web UI. This may allow impersonation of users whose session tokens are leaked.  

The security risk posed by this issue is significantly minimized when CLI access is restricted to a limited group of administrators.

Cloud NGFW and Prisma® Access are not affected by this vulnerability.

An information disclosure vulnerability in Palo Alto Networks PAN-OS® software enables an authenticated administrator to view session tokens of users authenticated to the firewall web UI. This may allow impersonation of users whose session tokens are leaked.  

The security risk posed by this issue is significantly minimized when CLI access is restricted to a limited group of administrators.

Cloud NGFW and Prisma® Access are not affected by this vulnerability.

EPSS

Процентиль: 12%
0.0004
Низкий

4.8 Medium

CVSS4

2.7 Low

CVSS3

Дефекты

CWE-497

Связанные уязвимости

CVSS3: 2.7
nvd
4 месяца назад

An information disclosure vulnerability in Palo Alto Networks PAN-OS® software enables an authenticated administrator to view session tokens of users authenticated to the firewall web UI. This may allow impersonation of users whose session tokens are leaked.   The security risk posed by this issue is significantly minimized when CLI access is restricted to a limited group of administrators. Cloud NGFW and Prisma® Access are not affected by this vulnerability.

EPSS

Процентиль: 12%
0.0004
Низкий

4.8 Medium

CVSS4

2.7 Low

CVSS3

Дефекты

CWE-497