CVE-2017-9458Critical

CVE-2017-9458 XML External Entity (XXE) in PAN-OS

Published
August 30, 2017
Last Modified
August 30, 2017

🔗 CVE IDs covered (1)

📋 Description

A vulnerability exists in PAN-OS’s GlobalProtect internal and external gateway interface that could allow for XML External Entity (XXE) attack. PAN-OS does not properly parse XML input. (Ref # PAN-75688 / CVE-2017-9458) Successful exploitation of this issue may allow disclosure of information, denial of service or server side request forgery. This issue affects PAN-OS 6.1.17 and earlier, PAN-OS 7.0.16 and earlier, PAN-OS 7.1.11 and earlier, PAN-OS 8.0.2 and earlier

🎯 Affected products1

  • PAN-OS

✅ Remediation

PAN-OS 6.1.18 and later, PAN-OS 7.0.17 and later, PAN-OS 7.1.12 and later, PAN-OS 8.0.3 and later Workarounds and mitigations: Customers that have not configured GlobalProtect are not affected by this issue.

🔗 References (1)