QID 731161
Date Published: 2024-02-21
QID 731161: Palo Alto Networks (PAN-OS) Insufficient Session Expiration Vulnerability in the Web Interface (PAN-211664)
PAN-OS is the software that runs all Palo Alto Networks next-generation firewalls.
Web sessions in the management interface in Palo Alto Networks PAN-OS software do not expire in certain situations, making it susceptible to unauthorized access.
Affected Versions:
PAN-OS 11.0 versions earlier than PAN-OS 11.0.2
PAN-OS 10.2 versions earlier than PAN-OS 10.2.5
PAN-OS 10.1 versions earlier than PAN-OS 10.1.10-h1
PAN-OS 10.0 versions earlier than PAN-OS 10.0.12-h1
PAN-OS 9.1 versions earlier than PAN-OS 9.1.17
PAN-OS 9.0 versions earlier than PAN-OS 9.0.17-h2
QID Detection Logic (Unauthenticated):
This QID looks for the vulnerable version of PAN-OS.
Successful exploitation of this vulnerability may compromise the Confidentiality, Integrity, and Availability of data.
- PAN-211664 -
security.paloaltonetworks.com/CVE-2024-0008
CVEs related to QID 731161
| Advisory ID | Software | Component | Link |
|---|---|---|---|
| PAN-211664 |
|