CVE-2024-5916

PAN-OS: Cleartext Exposure of External System Secrets

Severity
Medium 6
CVSS 4.0
Exploited
Not listed
EPSS
0.002
16.2th percentile
Discovered by
Vendor
Published by the vendor
Published
Aug 14, 2024
Assigned by palo_alto

Description

An information exposure vulnerability in Palo Alto Networks PAN-OS software enables a local system administrator to unintentionally disclose secrets, passwords, and tokens of external systems. A read-only administrator who has access to the config log, can read secrets, passwords, and tokens to external systems.

Weakness: CWE-313

Affected products

Vendor Product Category Matched by
Palo Alto Networks Cloud NGFW Firewall / NGFW cna-assigner
Palo Alto Networks PAN-OS Firewall / NGFW cna-assigner
Palo Alto Networks Prisma Access SASE / SSE / Secure Web cna-assigner
Vendor-reported affected versions (3)
  • Palo Alto Networks · PAN-OS
  • Palo Alto Networks · Cloud NGFW
  • Palo Alto Networks · Prisma Access

Credit

Hari Yadavalli of Palo Alto Networks

Vendor remediation

This issue is fixed in PAN-OS 10.2.8, PAN-OS 11.0.4, and all later PAN-OS versions. This issue is fixed in Cloud NGFW on or after 8/15 on Azure, Cloud NGFW on or after 8/23 on AWS, and all later Cloud NGFW versions. You should also revoke the secrets, passwords, and tokens that are configured in all server profiles of affected PAN-OS firewalls (Device > Server Profiles) after upgrading PAN-OS.