Lucene search

K
cvelistPalo_altoCVELIST:CVE-2021-3037
HistoryApr 20, 2021 - 3:15 a.m.

CVE-2021-3037 PAN-OS: Secrets for scheduled configuration exports are logged in system logs

2021-04-2003:15:17
CWE-534
palo_alto
www.cve.org
3
palo alto networks
information exposure
system logs
cleartext username
password
ip address

CVSS3

2.3

Attack Vector

LOCAL

Attack Complexity

LOW

Privileges Required

HIGH

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

LOW

Integrity Impact

NONE

Availability Impact

NONE

CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:L/I:N/A:N

AI Score

3.8

Confidence

High

EPSS

0

Percentile

12.6%

An information exposure through log file vulnerability exists in Palo Alto Networks PAN-OS software where the connection details for a scheduled configuration export are logged in system logs. Logged information includes the cleartext username, password, and IP address used to export the PAN-OS configuration to the destination server.

CNA Affected

[
  {
    "product": "PAN-OS",
    "vendor": "Palo Alto Networks",
    "versions": [
      {
        "changes": [
          {
            "at": "8.1.19",
            "status": "unaffected"
          }
        ],
        "lessThan": "8.1.19",
        "status": "affected",
        "version": "8.1",
        "versionType": "custom"
      },
      {
        "changes": [
          {
            "at": "9.0.13",
            "status": "unaffected"
          }
        ],
        "lessThan": "9.0.13",
        "status": "affected",
        "version": "9.0",
        "versionType": "custom"
      },
      {
        "changes": [
          {
            "at": "9.1.4",
            "status": "unaffected"
          }
        ],
        "lessThan": "9.1.4",
        "status": "affected",
        "version": "9.1",
        "versionType": "custom"
      },
      {
        "lessThan": "10.0*",
        "status": "unaffected",
        "version": "10.0.0",
        "versionType": "custom"
      }
    ]
  }
]

CVSS3

2.3

Attack Vector

LOCAL

Attack Complexity

LOW

Privileges Required

HIGH

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

LOW

Integrity Impact

NONE

Availability Impact

NONE

CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:L/I:N/A:N

AI Score

3.8

Confidence

High

EPSS

0

Percentile

12.6%

Related for CVELIST:CVE-2021-3037