CVE-2015-4162

Severity

40%

Complexity

80%

Confidentiality

48%

CWE-611: Improper Restriction of XML External Entity Reference ('XXE')

XML external entity (XXE) vulnerability in the management interface in PAN-OS before 5.0.16, 6.x before 6.0.8, and 6.1.x before 6.1.4 allows remote authenticated administrators to obtain sensitive information via crafted XML data.

CWE-611: Improper Restriction of XML External Entity Reference ('XXE')

CVSS 2.0 Base Score 4. CVSS Attack Vector: network. CVSS Attack Complexity: low. CVSS Vector: (AV:N/AC:L/Au:S/C:P/I:N/A:N).

Overview

First reported 9 years ago

2015-06-02 14:59:00

Last updated 8 years ago

2016-11-28 19:27:00

Affected Software

Palo Alto Networks PAN-OS

paloaltonetworks pan-os 6.0

6.0

paloaltonetworks pan-os 6.0.1

6.0.1

paloaltonetworks pan-os 6.0.2

6.0.2

paloaltonetworks pan-os 6.0.3

6.0.3

paloaltonetworks pan-os 6.0.4

6.0.4

paloaltonetworks pan-os 6.0.5

6.0.5

paloaltonetworks pan-os 6.0.6

6.0.6

paloaltonetworks pan-os 6.0.7

6.0.7

paloaltonetworks pan-os 6.1.0

6.1.0

paloaltonetworks pan-os 6.1.1

6.1.1

paloaltonetworks pan-os 6.1.2

6.1.2

paloaltonetworks pan-os 6.1.3

6.1.3

Stay updated

ExploitPedia is constantly evolving. Sign up to receive a notification when we release additional functionality.

Get in touch

If you'd like to report a bug or have any suggestions for improvements then please do get in touch with us using this form. We will get back to you as soon as we can.