Описание
The App-ID cache feature in Palo Alto Networks PAN-OS before 4.0.14, 4.1.x before 4.1.11, and 5.0.x before 5.0.2 allows remote attackers to bypass intended security policies via crafted requests that trigger invalid caching, as demonstrated by incorrect identification of HTTP traffic as SIP traffic, aka Ref ID 47195.
Ссылки
- Exploit
- Exploit
Уязвимые конфигурации
Конфигурация 1Версия до 4.0.8 (включая)
Одно из
cpe:2.3:o:paloaltonetworks:pan-os:*:*:*:*:*:*:*:*
cpe:2.3:o:paloaltonetworks:pan-os:4.0.0:*:*:*:*:*:*:*
cpe:2.3:o:paloaltonetworks:pan-os:4.0.1:*:*:*:*:*:*:*
cpe:2.3:o:paloaltonetworks:pan-os:4.0.2:*:*:*:*:*:*:*
cpe:2.3:o:paloaltonetworks:pan-os:4.0.3:*:*:*:*:*:*:*
cpe:2.3:o:paloaltonetworks:pan-os:4.0.4:*:*:*:*:*:*:*
cpe:2.3:o:paloaltonetworks:pan-os:4.0.5:*:*:*:*:*:*:*
cpe:2.3:o:paloaltonetworks:pan-os:4.0.6:*:*:*:*:*:*:*
cpe:2.3:o:paloaltonetworks:pan-os:4.0.7:*:*:*:*:*:*:*
cpe:2.3:o:paloaltonetworks:pan-os:4.1.0:*:*:*:*:*:*:*
cpe:2.3:o:paloaltonetworks:pan-os:4.1.1:*:*:*:*:*:*:*
cpe:2.3:o:paloaltonetworks:pan-os:4.1.2:*:*:*:*:*:*:*
cpe:2.3:o:paloaltonetworks:pan-os:4.1.3:*:*:*:*:*:*:*
cpe:2.3:o:paloaltonetworks:pan-os:4.1.4:*:*:*:*:*:*:*
cpe:2.3:o:paloaltonetworks:pan-os:4.1.5:*:*:*:*:*:*:*
cpe:2.3:o:paloaltonetworks:pan-os:4.1.6:*:*:*:*:*:*:*
cpe:2.3:o:paloaltonetworks:pan-os:4.1.7:*:*:*:*:*:*:*
cpe:2.3:o:paloaltonetworks:pan-os:4.1.8:*:*:*:*:*:*:*
cpe:2.3:o:paloaltonetworks:pan-os:4.1.8-h3:*:*:*:*:*:*:*
cpe:2.3:o:paloaltonetworks:pan-os:4.1.9:*:*:*:*:*:*:*
cpe:2.3:o:paloaltonetworks:pan-os:4.1.10:*:*:*:*:*:*:*
cpe:2.3:o:paloaltonetworks:pan-os:5.0.0:*:*:*:*:*:*:*
cpe:2.3:o:paloaltonetworks:pan-os:5.0.0-h1:*:*:*:*:*:*:*
EPSS
Процентиль: 69%
0.00606
Низкий
4.3 Medium
CVSS2
Дефекты
CWE-264
Связанные уязвимости
github
больше 3 лет назад
The App-ID cache feature in Palo Alto Networks PAN-OS before 4.0.14, 4.1.x before 4.1.11, and 5.0.x before 5.0.2 allows remote attackers to bypass intended security policies via crafted requests that trigger invalid caching, as demonstrated by incorrect identification of HTTP traffic as SIP traffic, aka Ref ID 47195.
EPSS
Процентиль: 69%
0.00606
Низкий
4.3 Medium
CVSS2
Дефекты
CWE-264