PAN-SA-2016-0032MediumDisclosed before NVD

PAN-SA-2016-0032 Insecure Browser API Token Generation

Published
October 31, 2016
Last Modified
October 31, 2016

📋 Description

The Palo Alto Networks firewalls API browser does not properly use the REST API tokens. In a specific scenario, an attacker could steal the authentication token and perform calls to the firewall’s API. (Ref # PAN-61046/PAN-100428) This post-authentication issue requires the attacker to have access to a logged-in administrator’s browser. This issue affects PAN-OS 5.0.19 and earlier; PAN-OS 5.1.12 and earlier; PAN-OS 6.0.14 and earlier; PAN-OS 6.1.14 and earlier; PAN-OS 7.0.10 and earlier; PAN-OS 7.1.4 and earlier

🎯 Affected products1

  • PAN-OS

✅ Remediation

PAN-OS 5.0.20 and later; PAN-OS 5.1.13 and later; PAN-OS 6.0.15 and later; PAN-OS 6.1.15 and later; PAN-OS 7.0.11 and later; PAN-OS 7.1.5 and later

🔗 References (1)