QID 731160
Date Published: 2024-02-20
QID 731160: Palo Alto Networks (PAN-OS) Reflected Cross-Site Scripting (XSS) Vulnerability (PAN-175970)
PAN OS is the software that runs all Palo Alto Networks next-generation firewalls.
Affected Versions:
PAN-OS 10.1 versions earlier than PAN-OS 10.1.13
PAN-OS 10.0 versions earlier than PAN-OS 10.0.11
PAN-OS 9.1 versions earlier than PAN-OS 9.1.13
PAN-OS 9.0 versions earlier than PAN-OS 9.0.17
PAN-OS 8.1 versions earlier than PAN-OS 8.1.24
QID Detection Logic (Authenticated):
This QID looks for the vulnerable version of PAN-OS
NOTE: The QID marked as practice. This issue is applicable only to firewalls that are configured to use Captive Portal authentication.
A reflected cross-site scripting (XSS) vulnerability in the Captive Portal feature of Palo Alto Networks PAN-OS software enables execution of malicious JavaScript in the context of an authenticated Captive Portal users browser if that user clicks on a malicious link, allowing phishing attacks that could lead to credential theft.
Workaround:
Customers with a Threat Prevention subscription can block attacks for this vulnerability by enabling Threat ID 93070
- PAN-175970 -
security.paloaltonetworks.com/CVE-2024-0011
CVEs related to QID 731160
| Advisory ID | Software | Component | Link |
|---|---|---|---|
| PAN-175970 |
|