CVE-2017-15943

Severity CVSS v4.0:
Pending analysis
Type:
CWE-918 Server-Side Request Forgery (SSRF)
Publication date:
11/12/2017
Last modified:
13/05/2026

Description

The configuration file import for applications, spyware and vulnerability objects functionality in the web interface in Palo Alto Networks PAN-OS before 6.1.19, 7.0.x before 7.0.19, and 7.1.x before 7.1.14 allows remote attackers to conduct server-side request forgery (SSRF) attacks and consequently obtain sensitive information via vectors related to parsing of external entities.

Vulnerable products and versions

CPE From Up to
cpe:2.3:o:paloaltonetworks:pan-os:*:*:*:*:*:*:*:* 6.1.19 (excluding)
cpe:2.3:o:paloaltonetworks:pan-os:*:*:*:*:*:*:*:* 7.0.0 (including) 7.0.19 (excluding)
cpe:2.3:o:paloaltonetworks:pan-os:*:*:*:*:*:*:*:* 7.1.0 (including) 7.1.14 (excluding)