CVE-2024-0008Medium
CVE-2024-0008 PAN-OS: Insufficient Session Expiration Vulnerability in the Web Interface
Published
February 14, 2024
Last Modified
February 14, 2024
🔗 CVE IDs covered (1)
📋 Description
Web sessions in the management interface in Palo Alto Networks PAN-OS software do not expire in certain situations, making it susceptible to unauthorized access.
🎯 Affected products3
- PAN-OS
- Prisma Access
- Cloud NGFW
✅ Remediation
This issue is fixed in PAN-OS 9.0.17-h2, PAN-OS 9.1.17, PAN-OS 10.0.12-h1, PAN-OS 10.1.10-h1, PAN-OS 10.2.5, PAN-OS 11.0.2, and all later PAN-OS versions. Workarounds and mitigations: Ensure that inactivity-based screen locks are enforced on endpoints with access to the PAN-OS web interface.