CVE-2017-7945
Severity CVSS v4.0:
Pending analysis
Type:
Unavailable / Other
Publication date:
29/04/2017
Last modified:
20/04/2025
Description
The GlobalProtect external interface in Palo Alto Networks PAN-OS before 6.1.17, 7.x before 7.0.15, 7.1.x before 7.1.9, and 8.x before 8.0.2 provides different error messages for failed login attempts depending on whether the username exists, which allows remote attackers to enumerate account names and conduct brute-force attacks via a series of requests, aka PAN-SA-2017-0014 and PAN-72769.
Impact
Base Score 3.x
9.80
Severity 3.x
CRITICAL
Base Score 2.0
5.00
Severity 2.0
MEDIUM
Vulnerable products and versions
| CPE | From | Up to |
|---|---|---|
| cpe:2.3:o:paloaltonetworks:pan-os:*:*:*:*:*:*:*:* | 6.1.15 (including) | |
| cpe:2.3:o:paloaltonetworks:pan-os:7.0.0:*:*:*:*:*:*:* | ||
| cpe:2.3:o:paloaltonetworks:pan-os:7.0.1:*:*:*:*:*:*:* | ||
| cpe:2.3:o:paloaltonetworks:pan-os:7.0.2:*:*:*:*:*:*:* | ||
| cpe:2.3:o:paloaltonetworks:pan-os:7.0.3:*:*:*:*:*:*:* | ||
| cpe:2.3:o:paloaltonetworks:pan-os:7.0.4:*:*:*:*:*:*:* | ||
| cpe:2.3:o:paloaltonetworks:pan-os:7.0.5:*:*:*:*:*:*:* | ||
| cpe:2.3:o:paloaltonetworks:pan-os:7.0.5:h2:*:*:*:*:*:* | ||
| cpe:2.3:o:paloaltonetworks:pan-os:7.0.6:*:*:*:*:*:*:* | ||
| cpe:2.3:o:paloaltonetworks:pan-os:7.0.7:*:*:*:*:*:*:* | ||
| cpe:2.3:o:paloaltonetworks:pan-os:7.0.8:*:*:*:*:*:*:* | ||
| cpe:2.3:o:paloaltonetworks:pan-os:7.0.9:*:*:*:*:*:*:* | ||
| cpe:2.3:o:paloaltonetworks:pan-os:7.0.10:*:*:*:*:*:*:* | ||
| cpe:2.3:o:paloaltonetworks:pan-os:7.0.11:*:*:*:*:*:*:* | ||
| cpe:2.3:o:paloaltonetworks:pan-os:7.0.12:*:*:*:*:*:*:* |
To consult the complete list of CPE names with products and versions, see this page



