An improper privilege management vulnerability in Palo Alto Networks PAN-OS software enables an authenticated read-only administrator to revoke active XML API keys from the firewall and disrupt XML API usage.
The product does not properly assign, modify, track, or check privileges for an actor, creating an unintended sphere of control for that actor.
Name | Vendor | Start Version | End Version |
---|---|---|---|
Pan-os | Paloaltonetworks | 9.1.0 (including) | 9.1.17 (excluding) |
Pan-os | Paloaltonetworks | 10.0.0 (including) | 10.0.12 (including) |
Pan-os | Paloaltonetworks | 10.1.0 (including) | 10.1.11 (excluding) |
Pan-os | Paloaltonetworks | 10.2.0 (including) | 10.2.5 (excluding) |
Pan-os | Paloaltonetworks | 11.0.0 (including) | 11.0.2 (excluding) |