QID 731030
Date Published: 2023-12-18
QID 731030: Palo Alto Networks (PAN-OS) OS Command Injection Vulnerability In the Extensible Markup Language (XML) API (PAN-156560)
PAN OS is the software that runs all Palo Alto Networks next-generation firewalls.
Affected Versions:
PAN-OS 10.1 versions earlier than PAN-OS 10.1.6
PAN-OS 10 versions earlier than PAN-OS 10.0.12
PAN-OS 9.1 versions earlier than PAN-OS 9.1.15
PAN-OS 9.0 versions earlier than PAN-OS 9.0.17
PAN-OS 8.1 versions earlier than PAN-OS 8.1.24
QID Detection Logic (Authenticated):
This QID looks for the vulnerable version of PAN-OS
NOTE: This is marked as Practice as this issue requires the attacker to have authenticated access to the PAN-OS XML API.
A cross-site scripting (XSS) vulnerability in Palo Alto Networks PAN-OS software enables a malicious authenticated read-write administrator to store a JavaScript payload using the web interface. Then, when viewed by a properly authenticated administrator, the JavaScript payload executes and disguises all associated actions as performed by that unsuspecting authenticated administrator.
Workaround:
Customers with a Threat Prevention subscription can block attacks for this vulnerability by enabling Threat ID 91715 (introduced in Applications and Threats content update 8473). This issue requires the attacker to have authenticated access to the PAN-OS XML API. You can mitigate the impact of this issue by following the Best Practices for Securing Administrative Access in the PAN-OS technical documentation at https://docs.paloaltonetworks.com/best-practices.
- PAN-156560 -
security.paloaltonetworks.com/CVE-2023-6792
CVEs related to QID 731030
| Advisory ID | Software | Component | Link |
|---|---|---|---|
| PAN-156560 |
|