Multiple vulnerabilities patched in Palo Alto Networks PAN-OS (advisories.ncsc.nl)
0xBASE INTEL BRIEF
- Multiple XSS flaws in PAN-OS components
- IPv6 bypass of security policies
- Authentication bypass in Large Scale VPN
- Command injection gives root access
- DoS attacks crash firewalls
"Palo Alto Networks has fixed multiple vulnerabilities in PAN-OS affecting PA-Series and VM-Series firewalls and Panorama management platforms. The flaws include cross-site scripting, IPv6 packet processing issues, information disclosure, authentication bypass in Large Scale VPN, SSRF, command injection, and denial of service. Attackers can exploit these to execute code, bypass policies, or crash systems. Access to the management interface should be restricted."
no comments yet.