PAN-SA-2014-0001MediumDisclosed before NVD

PAN-SA-2014-0001 Management API Key Bypass

Published
January 29, 2014
Last Modified
January 29, 2014

📋 Description

An XML API key can be bypassed if a session has been authorized. This can be used in a CSRF or XSS attack. (Ref # 58976) This issue requires an authenticated administrator session to be successful. This issue affects PAN-OS version 4.1.15 and earlier; 5.0.9 and earlier; 5.1.4 and earlier.

🎯 Affected products1

  • PAN-OS

✅ Remediation

PAN-OS 4.1.16; 5.0.10 and 5.1.5 address this issue. Workarounds and mitigations: This issue affects the management interface of the device. Security appliance management best practices dictate that the management interface be isolated and strictly limited only to security administration personnel.

🔗 References (1)