CVE-2024-0008Medium

CVE-2024-0008 PAN-OS: Insufficient Session Expiration Vulnerability in the Web Interface

Published
February 14, 2024
Last Modified
February 14, 2024

🔗 CVE IDs covered (1)

📋 Description

Web sessions in the management interface in Palo Alto Networks PAN-OS software do not expire in certain situations, making it susceptible to unauthorized access.

🎯 Affected products3

  • PAN-OS
  • Prisma Access
  • Cloud NGFW

✅ Remediation

This issue is fixed in PAN-OS 9.0.17-h2, PAN-OS 9.1.17, PAN-OS 10.0.12-h1, PAN-OS 10.1.10-h1, PAN-OS 10.2.5, PAN-OS 11.0.2, and all later PAN-OS versions. Workarounds and mitigations: Ensure that inactivity-based screen locks are enforced on endpoints with access to the PAN-OS web interface.

🔗 References (1)