CVE-2017-15943Server-Side Request Forgery in Paloaltonetworks Pan-os

Severity
5.3MEDIUMNVD
EPSS
0.6%
top 31.48%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedDec 11
Latest updateMay 13

Description

The configuration file import for applications, spyware and vulnerability objects functionality in the web interface in Palo Alto Networks PAN-OS before 6.1.19, 7.0.x before 7.0.19, and 7.1.x before 7.1.14 allows remote attackers to conduct server-side request forgery (SSRF) attacks and consequently obtain sensitive information via vectors related to parsing of external entities.

CVSS vector

CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:NExploitability: 3.9 | Impact: 1.4

Affected Packages2 packages

NVDpaloaltonetworks/pan-os7.0.07.0.19+2
Palo Altopaloalto/pan-os

🔴Vulnerability Details

2
GHSA
GHSA-rh48-33f7-4q29: The configuration file import for applications, spyware and vulnerability objects functionality in the web interface in Palo Alto Networks PAN-OS befo2022-05-13
CVEList
CVE-2017-15943: The configuration file import for applications, spyware and vulnerability objects functionality in the web interface in Palo Alto Networks PAN-OS befo2017-12-11

📋Vendor Advisories

1
Palo Alto
Server-Side Request Forgery in PAN-OS2017-12-06
CVE-2017-15943 — Server-Side Request Forgery | cvebase