CVE Vulnerabilities

CVE-2023-6793

Improper Privilege Management

Published: Dec 13, 2023 | Modified: Dec 18, 2023
CVSS 3.x
2.7
LOW
Source:
NVD
CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:N/I:N/A:L
CVSS 2.x
RedHat/V2
RedHat/V3
Ubuntu

An improper privilege management vulnerability in Palo Alto Networks PAN-OS software enables an authenticated read-only administrator to revoke active XML API keys from the firewall and disrupt XML API usage.

Weakness

The product does not properly assign, modify, track, or check privileges for an actor, creating an unintended sphere of control for that actor.

Affected Software

Name Vendor Start Version End Version
Pan-os Paloaltonetworks 9.1.0 (including) 9.1.17 (excluding)
Pan-os Paloaltonetworks 10.0.0 (including) 10.0.12 (including)
Pan-os Paloaltonetworks 10.1.0 (including) 10.1.11 (excluding)
Pan-os Paloaltonetworks 10.2.0 (including) 10.2.5 (excluding)
Pan-os Paloaltonetworks 11.0.0 (including) 11.0.2 (excluding)

Potential Mitigations

References