QID 731032
Date Published: 2023-12-18
QID 731032: Palo Alto Networks (PAN-OS) File Upload Vulnerability In The Web Interface (PAN-139152 and PAN-131835)
PAN OS is the software that runs all Palo Alto Networks next-generation firewalls.
Affected Versions:
PAN-OS 9.1 versions earlier than PAN-OS 9.1.14
PAN-OS 9.0 versions earlier than PAN-OS 9.0.17-h1
PAN-OS 8.1 versions earlier than PAN-OS 8.1.26
QID Detection Logic (Authenticated):
This QID looks for the vulnerable version of PAN-OS
NOTE: This is marked as Practice as this issue requires the attacker to have authenticated access to the PAN-OS web interface.
An arbitrary file upload vulnerability in Palo Alto Networks PAN-OS software enables an authenticated read-write administrator with access to the web interface to disrupt system processes and potentially execute arbitrary code with limited privileges on the firewall.
Solution
Customer are advised to refer to PAN-139152 and PAN-131835 for more information about this vulnerability.
Workaround:
This issue requires the attacker to have authenticated access to the PAN-OS web interface. You can mitigate the impact of this issue by following the Best Practices for Securing Administrative Access in the PAN-OS technical documentation at https://docs.paloaltonetworks.com/best-practices.
Workaround:
This issue requires the attacker to have authenticated access to the PAN-OS web interface. You can mitigate the impact of this issue by following the Best Practices for Securing Administrative Access in the PAN-OS technical documentation at https://docs.paloaltonetworks.com/best-practices.
Vendor References
- PAN-131835 -
security.paloaltonetworks.com/CVE-2023-6794 - PAN-139152 -
security.paloaltonetworks.com/CVE-2023-6794
CVEs related to QID 731032
Software Advisories
| Advisory ID | Software | Component | Link |
|---|---|---|---|
| PAN-139152 and PAN-131835 |
|