CVE Vulnerabilities

CVE-2023-6793

Improper Privilege Management

Published: Dec 13, 2023 | Modified: Nov 21, 2024
CVSS 3.x
2.7
LOW
Source:
NVD
CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:N/I:N/A:L
CVSS 2.x
RedHat/V2
RedHat/V3
Ubuntu
root.io logo minimus.io logo echo.ai logo

An improper privilege management vulnerability in Palo Alto Networks PAN-OS software enables an authenticated read-only administrator to revoke active XML API keys from the firewall and disrupt XML API usage.

Weakness

The product does not properly assign, modify, track, or check privileges for an actor, creating an unintended sphere of control for that actor.

Affected Software

NameVendorStart VersionEnd Version
Pan-osPaloaltonetworks9.1.0 (including)9.1.17 (excluding)
Pan-osPaloaltonetworks10.0.0 (including)10.0.12 (including)
Pan-osPaloaltonetworks10.1.0 (including)10.1.11 (excluding)
Pan-osPaloaltonetworks10.2.0 (including)10.2.5 (excluding)
Pan-osPaloaltonetworks11.0.0 (including)11.0.2 (excluding)

Potential Mitigations

References