An information disclosure vulnerability in the URL Filtering feature of Palo Alto Networks PAN-OS® software enables an unauthenticated user with network access to obtain sensitive information.
Panorama is not impacted by this vulnerability.
CVSS Vector: CVSS:4.0/AV:A/AC:L/AT:P/PR:L/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N/E:U/AU:N/R:U/V:D/RE:M/U:Amber
CVSS Score: 0.5
The risk of exploitation is lower for Prisma Access as it requires an authenticated user and the external network access to the management interface is restricted.
| Exploitability Metrics |
Vulnerable System Impact Metrics |
Subsequent System Impact Metrics |
| Attack Vector |
Adjacent |
Confidentiality |
Low |
Confidentiality |
None |
| Attack Complexity |
Low |
Integrity |
None |
Integrity |
None |
| Attack Requirements |
Present |
Availability |
None |
Availability |
None |
| Privileges Required |
Low |
| User Interaction |
None |
The risk of exploitation is lower for Prisma Access as it requires an authenticated user and the external network access to the management interface is restricted.
CVSS 4.0
Palo Alto Networks is not aware of any malicious exploitation of this issue.
Customers can mitigate this issue by limiting the Response Page Variables (https://docs.paloaltonetworks.com/advanced-url-filtering/administration/url-filtering-features/url-filtering-response-pages/url-filtering-response-page-objects#idf281835b-ab7c-4553-93e2-46967443f9f9_id8313c239-3cf5-4bee-8909-e8e047b70b44) on their response page to only those in the Predefined URL Filtering Response Pages (https://docs.paloaltonetworks.com/advanced-url-filtering/administration/url-filtering-features/url-filtering-response-pages/predefined-url-filtering-response-pages#ida9f33d58-e2ea-4a6f-9b4f-0ab42fd6921f). (https://docs.paloaltonetworks.com/advanced-url-filtering/administration/url-filtering-features/url-filtering-response-pages/predefined-url-filtering-response-pages#ida9f33d58-e2ea-4a6f-9b4f-0ab42fd6921f) The variables that are included in our predefined response pages (user, url, category, pan_form) are not impacted by this vulnerability.