Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-p4fj-c8rg-ggm6

Опубликовано: 09 окт. 2025
Источник: github
Github: Не прошло ревью
CVSS4: 4.8
CVSS3: 2.7

Описание

An information disclosure vulnerability in Palo Alto Networks PAN-OS® software enables an authenticated administrator to view session tokens of users authenticated to the firewall web UI. This may allow impersonation of users whose session tokens are leaked.  

The security risk posed by this issue is significantly minimized when CLI access is restricted to a limited group of administrators.

Cloud NGFW and Prisma® Access are not affected by this vulnerability.

An information disclosure vulnerability in Palo Alto Networks PAN-OS® software enables an authenticated administrator to view session tokens of users authenticated to the firewall web UI. This may allow impersonation of users whose session tokens are leaked.  

The security risk posed by this issue is significantly minimized when CLI access is restricted to a limited group of administrators.

Cloud NGFW and Prisma® Access are not affected by this vulnerability.

EPSS

Процентиль: 13%
0.00225
Низкий

4.8 Medium

CVSS4

2.7 Low

CVSS3

Дефекты

CWE-497

Связанные уязвимости

CVSS3: 2.7
nvd
10 месяцев назад

An information disclosure vulnerability in Palo Alto Networks PAN-OS® software enables an authenticated administrator to view session tokens of users authenticated to the firewall web UI. This may allow impersonation of users whose session tokens are leaked.   The security risk posed by this issue is significantly minimized when CLI access is restricted to a limited group of administrators. Cloud NGFW and Prisma® Access are not affected by this vulnerability.

CVSS3: 2.7
fstec
10 месяцев назад

Уязвимость операционной системы PAN-OS, позволяющая нарушителю получить несанкционированный доступ к защищаемой информации

EPSS

Процентиль: 13%
0.00225
Низкий

4.8 Medium

CVSS4

2.7 Low

CVSS3

Дефекты

CWE-497