CVE-2024-8688Medium

CVE-2024-8688 PAN-OS: Arbitrary File Read Vulnerability in the Command Line Interface (CLI)

Published
September 11, 2024
Last Modified
September 11, 2024

🔗 CVE IDs covered (1)

📋 Description

An improper neutralization of matching symbols vulnerability in the Palo Alto Networks PAN-OS command line interface (CLI) enables authenticated administrators (including read-only administrators) with access to the CLI to to read arbitrary files on the firewall.

🎯 Affected products3

  • PAN-OS
  • Cloud NGFW
  • Prisma Access

✅ Remediation

This issue is fixed in PAN-OS 9.1.15, PAN-OS 10.0.10, PAN-OS 10.1.1, and all later PAN-OS versions.

🔗 References (1)