CVE-2013-5663Paloaltonetworks Pan-os vulnerability

CWE-2644 documents4 sources
Severity
4.3MEDIUMNVD
EPSS
0.6%
top 30.32%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedAug 31
Latest updateMay 14

Description

The App-ID cache feature in Palo Alto Networks PAN-OS before 4.0.14, 4.1.x before 4.1.11, and 5.0.x before 5.0.2 allows remote attackers to bypass intended security policies via crafted requests that trigger invalid caching, as demonstrated by incorrect identification of HTTP traffic as SIP traffic, aka Ref ID 47195.

CVSS vector

AV:N/AC:M/C:N/I:P/A:NExploitability: 8.6 | Impact: 2.9

Affected Packages2 packages

Palo Altopaloalto/pan-os

🔴Vulnerability Details

2
GHSA
GHSA-h2xj-j4rp-84f4: The App-ID cache feature in Palo Alto Networks PAN-OS before 42022-05-14
CVEList
CVE-2013-5663: The App-ID cache feature in Palo Alto Networks PAN-OS before 42013-08-31

📋Vendor Advisories

1
Palo Alto
App-ID Cache Poisoning2013-01-07
CVE-2013-5663 — Paloaltonetworks Pan-os vulnerability | cvebase