PAN-SA-2014-0002MediumDisclosed before NVD

PAN-SA-2014-0002 Cross-site Scripting Vulnerability

Published
January 29, 2014
Last Modified
January 29, 2014

📋 Description

A cross-site scripting vulnerability exists in the web-based device management interface whereby data provided by the user is echoed back to the user without sanitization. (Ref # 59010) This issue affects the management interface of the device, requiring a malicious administrator to upload malicious script to the device. This issue affects PAN-OS version 5.0.9 and earlier; 5.1.4 and earlier.

🎯 Affected products1

  • PAN-OS

✅ Remediation

PAN-OS 5.0.10 and 5.1.5 address this issue. Workarounds and mitigations: This issue affects the management interface of the device. Security appliance management best practices dictate that the management interface be isolated and strictly limited only to security administration personnel.

🔗 References (1)