CVE-2017-7644
Severity CVSS v4.0:
Pending analysis
Type:
CWE-200
Information Leak / Disclosure
Publication date:
29/04/2017
Last modified:
20/04/2025
Description
The Management Web Interface in Palo Alto Networks PAN-OS before 6.1.17, 7.x before 7.0.15, and 7.1.x before 7.1.9 allows remote authenticated users to obtain sensitive information by leveraging incorrect permission validation, aka PAN-SA-2017-0013 and PAN-70541.
Impact
Base Score 3.x
6.50
Severity 3.x
MEDIUM
Base Score 2.0
4.00
Severity 2.0
MEDIUM
Vulnerable products and versions
| CPE | From | Up to |
|---|---|---|
| cpe:2.3:o:paloaltonetworks:pan-os:*:*:*:*:*:*:*:* | 6.1.15 (including) | |
| cpe:2.3:o:paloaltonetworks:pan-os:7.0.0:*:*:*:*:*:*:* | ||
| cpe:2.3:o:paloaltonetworks:pan-os:7.0.1:*:*:*:*:*:*:* | ||
| cpe:2.3:o:paloaltonetworks:pan-os:7.0.2:*:*:*:*:*:*:* | ||
| cpe:2.3:o:paloaltonetworks:pan-os:7.0.3:*:*:*:*:*:*:* | ||
| cpe:2.3:o:paloaltonetworks:pan-os:7.0.4:*:*:*:*:*:*:* | ||
| cpe:2.3:o:paloaltonetworks:pan-os:7.0.5:*:*:*:*:*:*:* | ||
| cpe:2.3:o:paloaltonetworks:pan-os:7.0.5:h2:*:*:*:*:*:* | ||
| cpe:2.3:o:paloaltonetworks:pan-os:7.0.6:*:*:*:*:*:*:* | ||
| cpe:2.3:o:paloaltonetworks:pan-os:7.0.7:*:*:*:*:*:*:* | ||
| cpe:2.3:o:paloaltonetworks:pan-os:7.0.8:*:*:*:*:*:*:* | ||
| cpe:2.3:o:paloaltonetworks:pan-os:7.0.9:*:*:*:*:*:*:* | ||
| cpe:2.3:o:paloaltonetworks:pan-os:7.0.10:*:*:*:*:*:*:* | ||
| cpe:2.3:o:paloaltonetworks:pan-os:7.0.11:*:*:*:*:*:*:* | ||
| cpe:2.3:o:paloaltonetworks:pan-os:7.0.12:*:*:*:*:*:*:* |
To consult the complete list of CPE names with products and versions, see this page



