CVE-2018-9242

Severity CVSS v4.0:
Pending analysis
Type:
CWE-20 Input Validation
Publication date:
03/07/2018
Last modified:
17/02/2020

Description

The PAN-OS management web interface page in PAN-OS 6.1.20 and earlier, PAN-OS 7.1.16 and earlier, PAN-OS 8.0.9 and earlier may allow an attacker to delete files in the system via specific request parameters.

Vulnerable products and versions

CPE From Up to
cpe:2.3:o:paloaltonetworks:pan-os:*:*:*:*:*:*:*:* 6.0.0 (excluding) 6.1.20 (including)
cpe:2.3:o:paloaltonetworks:pan-os:*:*:*:*:*:*:*:* 7.1.0 (including) 7.1.16 (including)
cpe:2.3:o:paloaltonetworks:pan-os:*:*:*:*:*:*:*:* 8.0.0 (excluding) 8.0.9 (including)