Lucene search

K
paloaltoPalo Alto Networks Product Security Incident Response TeamPA-CVE-2023-4863
HistoryOct 02, 2023 - 11:40 p.m.

Impact of libwebp Vulnerability CVE-2023-4863

2023-10-0223:40:00
Palo Alto Networks Product Security Incident Response Team
securityadvisories.paloaltonetworks.com
41
palo alto networks
libwebp
vulnerability
cve-2023-4863
threat prevention
threat id 94394
content update 8757
impact
exploitation
software

CVSS3

8.8

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

NONE

User Interaction

REQUIRED

Scope

UNCHANGED

Confidentiality Impact

HIGH

Integrity Impact

HIGH

Availability Impact

HIGH

CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H

EPSS

0.629

Percentile

97.9%

The Palo Alto Networks Product Security Assurance team has evaluated the recently disclosed critical libwebp vulnerability (CVE-2023-4863) as it relates to our products. While PAN-OS 10.2 and later versions include this library, PAN-OS software does not offer any scenarios required for the successful exploitation of this vulnerability and is not impacted.

No other Palo Alto Networks products are known to contain the vulnerable library and be impacted by this issue at this time.

Work around:
Customers with a Threat Prevention subscription can block attacks for this vulnerability by enabling Threat ID 94394 (Applications and Threats content update 8757).

CVSS3

8.8

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

NONE

User Interaction

REQUIRED

Scope

UNCHANGED

Confidentiality Impact

HIGH

Integrity Impact

HIGH

Availability Impact

HIGH

CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H

EPSS

0.629

Percentile

97.9%