QID 731159
Date Published: 2024-02-20
QID 731159: Palo Alto Networks (PAN-OS) Reflected Cross-Site Scripting (XSS) Vulnerability (PAN-216858)
PAN OS is the software that runs all Palo Alto Networks next-generation firewalls.
Affected Versions:
PAN-OS 10.1 versions earlier than PAN-OS 10.1.11-h1
PAN-OS 9.1 versions earlier than PAN-OS 9.1.17
PAN-OS 9.0 versions earlier than PAN-OS 9.0.17-h4
QID Detection Logic (Authenticated):
This QID looks for the vulnerable version of PAN-OS
NOTE: The QID marked as practice. This issue is applicable only to PAN-OS firewall configurations with a GlobalProtect portal enabled.
A reflected cross-site scripting (XSS) vulnerability in the Global Protect portal feature of Palo Alto Networks PAN-OS software enables execution of malicious JavaScript in the context of a users browser if that user clicks on a malicious link, allowing phishing attacks that could lead to credential theft.
Workaround:
Customers with a Threat Prevention subscription can block attacks for this vulnerability by enabling Threat ID 94972
- PAN-216858 -
security.paloaltonetworks.com/CVE-2024-0010
CVEs related to QID 731159
| Advisory ID | Software | Component | Link |
|---|---|---|---|
| PAN-216858 |
|