VDB
CISA-2023-0005
CISA-2023-0005
PUBLISHED
CVSS 4.1 MEDIUM
Reported by palo_alto · Published April 12, 2023
A vulnerability in Palo Alto Networks PAN-OS software enables an authenticated administrator to expose the plaintext values of secrets stored in the device configuration and encrypted API keys.
Risk Scores
CVSS 3.1
4.1
CVSS:3.1/AV:L/AC:H/PR:H/UI:N/S:U/C:H/I:N/A:N
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Palo Alto Networks | PAN-OS | 11.0, 10.2, 10.1 |
| Palo Alto Networks | Prisma Access | All |
| Palo Alto Networks | Cloud NGFW | All |
| Palo Alto Networks | Prisma Access | All, * |
| Palo Alto Networks | PAN-OS | 10.1, 8.1, 10.2 |
| Palo Alto Networks | Cloud NGFW | All, All |
Timeline
- Apr 12, 2023 CVE Published
- Feb 10, 2025 CVE Updated