PAN-SA-2014-0001MediumDisclosed before NVD
PAN-SA-2014-0001 Management API Key Bypass
📋 Description
An XML API key can be bypassed if a session has been authorized. This can be used in a CSRF or XSS attack. (Ref # 58976) This issue requires an authenticated administrator session to be successful. This issue affects PAN-OS version 4.1.15 and earlier; 5.0.9 and earlier; 5.1.4 and earlier.
🎯 Affected products1
- PAN-OS
✅ Remediation
PAN-OS 4.1.16; 5.0.10 and 5.1.5 address this issue. Workarounds and mitigations: This issue affects the management interface of the device. Security appliance management best practices dictate that the management interface be isolated and strictly limited only to security administration personnel.