CVE Database
/

CVE-2017-15943

Back to search

CVE-2017-15943

Published: Dec 11, 2017

Modified: Aug 5, 2024

PUBLISHED

Description

The configuration file import for applications, spyware and vulnerability objects functionality in the web interface in Palo Alto Networks PAN-OS before 6.1.19, 7.0.x before 7.0.19, and 7.1.x before 7.1.14 allows remote attackers to conduct server-side request forgery (SSRF) attacks and consequently obtain sensitive information via vectors related to parsing of external entities.

VendorProductVersions

n/a

n/a

affected
n/a

References

1040005
vdb-entry
x_refsource_SECTRACK
102074
vdb-entry
x_refsource_BID

Security Training

Train your team to recognize and prevent security threats with our comprehensive security awareness program.

Start Training

Vulnerability Scanning

Discover vulnerabilities in your applications and infrastructure before attackers do.

Scan Now