CVE Database
/

CVE-2021-3031

Back to search

CVE-2021-3031

Published: Jan 13, 2021

Modified: Sep 16, 2024

PUBLISHED

CVSS v3.1

4.3

MEDIUM

Description

Padding bytes in Ethernet packets on PA-200, PA-220, PA-500, PA-800, PA-2000 Series, PA-3000 Series, PA-3200 Series, PA-5200 Series, and PA-7000 Series firewalls are not cleared before the data frame is created. This leaks a small amount of random information from the firewall memory into the Ethernet packets. An attacker on the same Ethernet subnet as the PAN-OS firewall is able to collect potentially sensitive information from these packets. This issue is also known as Etherleak and is detected by security scanners as CVE-2003-0001. This issue impacts: PAN-OS 8.1 version earlier than PAN-OS 8.1.18; PAN-OS 9.0 versions earlier than PAN-OS 9.0.12; PAN-OS 9.1 versions earlier than PAN-OS 9.1.5.

VendorProductVersions

Palo Alto Networks

PAN-OS

affected
8.1 - < 8.1.18
affected
9.0 - < 9.0.12
affected
9.1 - < 9.1.5

Palo Alto Networks

PAN-OS

unaffected
10.0.*
unaffected
8.1.18 - < 8.1*
unaffected
9.0.12 - < 9.0*
unaffected
9.1.5 - < 9.1*

Weaknesses (CWE)

CVSS v3.1 Details

CVSS v3.1 Vector

CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N

Attack Vector

Adjacent

Attack Complexity

Low

Privileges Required

None

User Interaction

None

Scope

Unchanged

Confidentiality

Low

Integrity

None

Availability

None

Security Training

Train your team to recognize and prevent security threats with our comprehensive security awareness program.

Start Training

Vulnerability Scanning

Discover vulnerabilities in your applications and infrastructure before attackers do.

Scan Now