CVE Database
/

CVE-2019-1575

Back to search

CVE-2019-1575

Published: Jul 16, 2019

Modified: Aug 4, 2024

PUBLISHED

Description

Information disclosure in PAN-OS 7.1.23 and earlier, PAN-OS 8.0.18 and earlier, PAN-OS 8.1.8-h4 and earlier, and PAN-OS 9.0.2 and earlier may allow for an authenticated user with read-only privileges to extract the API key of the device and/or the username/password from the XML API (in PAN-OS) and possibly escalate privileges granted to them.

VendorProductVersions

Palo Alto

Palo Alto Networks PAN-OS

affected
PAN-OS 7.1.23 and earlier
affected
PAN-OS 8.0.18 and earlier
affected
PAN-OS 8.1.8-h4 and earlier
affected
and PAN-OS 9.0.2-h3

References

109176
vdb-entry
x_refsource_BID

Security Training

Train your team to recognize and prevent security threats with our comprehensive security awareness program.

Start Training

Vulnerability Scanning

Discover vulnerabilities in your applications and infrastructure before attackers do.

Scan Now