"value":"Missing XML validation vulnerability in the PAN-OS web interface on Palo Alto Networks PAN-OS software allows authenticated users to inject arbitrary XML that results in privilege escalation. This issue affects PAN-OS 8.1 versions earlier than PAN-OS 8.1.12 and PAN-OS 9.0 versions earlier than PAN-OS 9.0.6. This issue does not affect PAN-OS 7.1, PAN-OS 8.0, or PAN-OS 9.1 or later versions."
"value":"This issue is fixed in PAN-OS 8.1.12, PAN-OS 9.0.6, and all later versions.\n"
}
],
"source":{
"defect":[
"PAN-124593"
],
"discovery":"EXTERNAL"
},
"work_around":[
{
"lang":"eng",
"value":"This issue affects the web-based management interface of the appliance. Access to the web-based management interface of the appliance should be limited strictly to only trusted users, hosts, and networks.\n"