"value":"Web sessions in the management interface in Palo Alto Networks PAN-OS software do not expire in certain situations, making it susceptible to unauthorized access."
"value":"Ensure that inactivity-based screen locks are enforced on endpoints with access to the PAN-OS web interface."
}
],
"value":"Ensure that inactivity-based screen locks are enforced on endpoints with access to the PAN-OS web interface."
}
],
"exploit":[
{
"lang":"en",
"supportingMedia":[
{
"base64":false,
"type":"text/html",
"value":"Palo Alto Networks is not aware of any malicious exploitation of this issue.<br>"
}
],
"value":"Palo Alto Networks is not aware of any malicious exploitation of this issue.\n"
}
],
"solution":[
{
"lang":"en",
"supportingMedia":[
{
"base64":false,
"type":"text/html",
"value":"This issue is fixed in PAN-OS 9.0.17-h2, PAN-OS 9.1.17, PAN-OS 10.0.12-h1, PAN-OS 10.1.10-h1, PAN-OS 10.2.5, PAN-OS 11.0.2, and all later PAN-OS versions."
}
],
"value":"This issue is fixed in PAN-OS 9.0.17-h2, PAN-OS 9.1.17, PAN-OS 10.0.12-h1, PAN-OS 10.1.10-h1, PAN-OS 10.2.5, PAN-OS 11.0.2, and all later PAN-OS versions."
}
],
"credits":[
{
"lang":"en",
"value":"Palo Alto Networks thanks Brian Yaklin for discovering and reporting this issue."