PAN-SA-2016-0007MediumDisclosed before NVD

PAN-SA-2016-0007 User-ID Agent API Access

Published
May 23, 2016
Last Modified
May 23, 2016

📋 Description

The Palo Alto Networks User-ID agent for Windows implements an API to retrieve the agent’s configuration. This TLS-secured API call returns encrypted credentials to the domain account configured on the User-ID agent, which has read-only rights for Security Event Logs on Domain Controllers. Anyone with access to the User-ID agent Service TCP port can retrieve this encrypted password by invoking this API. (Ref #93349) Only users who possess network level access to the User-ID agent Service TCP port can invoke this API. This issue affects Windows devices running all versions of User-ID agent up to 7.0.3

🎯 Affected products1

  • User-ID Agent

✅ Remediation

User-ID agent 7.0.4 and later releases Workarounds and mitigations: Only users on the network can access the User-ID agent Service TCP port and make this API call. Palo Alto Networks recommends that the host running the User-ID agent and the Domain Controllers share the same network-level access restrictions. The User-ID agent should be able to reach only the Domain Controllers and only accessible by Palo Alto Networks firewalls to prevent direct access by malevolent entities.

🔗 References (1)