Skip to main content

Palo Alto PAN-OS JavaScript Execution and Input Validation Vulnerabilities

Last Update Date: 24 Oct 2016 14:39 Release Date: 24 Oct 2016 3587 Views

RISK: Medium Risk

TYPE: Operating Systems - Networks OS

TYPE: Networks OS

Two vulnerabilities were identified in Palo Alto PAN-OS. A remote user can conduct JavaScript execution attacks and cross-site scripting attacks on the target service.


Impact

  • Cross-Site Scripting
  • Remote Code Execution
  • Information Disclosure

System / Technologies affected

  • Version 5.0.19 and prior
  • Version 5.1.12 and prior
  • Version 6.0.13 and prior
  • Version 6.1.12 and prior
  • Version 7.0.7 and prior
  • Version 7.1.4 and prior

Solutions

Before installation of the software, please visit the software manufacturer web-site for more details.

  • Update to version 5.0.20
  • Update to version 5.1.13
  • Update to version 6.0.15
  • Update to version 6.1.14
  • Update to version 7.0.10
  • Update to version 7.1.5

Vulnerability Identifier

  • No CVE information is available

Source


Related Link