CVE-2023-6793Improper Privilege Management in Palo Alto Networks Pan-os

Severity
2.7LOWNVD
EPSS
0.1%
top 76.60%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedDec 13

Description

An improper privilege management vulnerability in Palo Alto Networks PAN-OS software enables an authenticated read-only administrator to revoke active XML API keys from the firewall and disrupt XML API usage.

CVSS vector

CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:N/I:N/A:LExploitability: 1.2 | Impact: 1.4

Affected Packages5 packages

NVDpaloaltonetworks/pan-os9.1.09.1.17+4
CVEListV5palo_alto_networks/pan-os9.09.0.17-h4+5
Palo Altopaloalto/pan-os

🔴Vulnerability Details

2
GHSA
GHSA-6q2r-m35r-8mf3: An improper privilege management vulnerability in Palo Alto Networks PAN-OS software enables an authenticated read-only administrator to revoke active2023-12-13
CVEList
PAN-OS: XML API Keys Revoked by Read-Only PAN-OS Administrator2023-12-13

📋Vendor Advisories

1
Palo Alto
PAN-OS: XML API Keys Revoked by Read-Only PAN-OS Administrator2023-12-13
CVE-2023-6793 — Improper Privilege Management in Palo | cvebase