CVE-2023-38545None

CVE-2023-38545 Impact of curl and libcurl Vulnerabilities (CVE-2023-38545, CVE-2023-38546)

Published
October 12, 2023
Last Modified
October 31, 2023

🔗 CVE IDs covered (1)

📋 Description

The Palo Alto Networks Product Security Assurance team has evaluated the curl and libcurl vulnerabilities (CVE-2023-38545, CVE-2023-38546) that were disclosed on October 11, 2023 as they relate to our products. At this time, there are no demonstrated scenarios that enable successful exploitation of these vulnerabilities in our products.

🎯 Affected products7

  • PAN-OS
  • Prisma Cloud
  • Cloud NGFW
  • Prisma Access
  • Prisma SD-WAN ION
  • Cortex XDR
  • Cortex XDR Agent

✅ Remediation

No software updates are required at this time. Workarounds and mitigations: Customers with a Threat Prevention subscription can block attacks for CVE-2023-38545 by enabling Threat ID 94436 (Applications and Threats content update 8764).

🔗 References (1)