CVE-2023-0005Exposure of Sensitive System Information to an Unauthorized Control Sphere in Palo Alto Networks Pan-os

Severity
4.9MEDIUMNVD
CNA4.1
EPSS
0.3%
top 50.71%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedApr 12
Latest updateDec 30

Description

A vulnerability in Palo Alto Networks PAN-OS software enables an authenticated administrator to expose the plaintext values of secrets stored in the device configuration and encrypted API keys.

CVSS vector

CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:N/A:NExploitability: 1.2 | Impact: 3.6

Affected Packages5 packages

NVDpaloaltonetworks/pan-os8.1.08.1.24+5
CVEListV5palo_alto_networks/pan-os10.210.2.3+5
Palo Altopaloalto/pan-os

🔴Vulnerability Details

3
OSV
s390/vmem: split pages when debug pagealloc is enabled2025-12-30
CVEList
PAN-OS: Exposure of Sensitive Information Vulnerability2023-04-12
GHSA
GHSA-fm8c-g4fr-mj3j: A vulnerability in Palo Alto Networks PAN-OS software enables an authenticated administrator to expose the plaintext values of secrets stored in the d2023-04-12

📋Vendor Advisories

3
Red Hat
kernel: s390/vmem: split pages when debug pagealloc is enabled2025-12-30
Palo Alto
PAN-OS: Exposure of Sensitive Information Vulnerability2023-04-12
VMware
VMware vRealize Orchestrator update addresses an XML External Entity (XXE) vulnerability (CVE-2023-20855)2023-02-21

🕵️Threat Intelligence

1
Microsoft
Detecting and mitigating elevation-of-privilege exploit for CVE-2017-0005 | Microsoft Security Blog2017-03-27
CVE-2023-0005 — Palo Alto Networks Pan-os vulnerability | cvebase