PAN-OS: Multiple Cross-Site Scripting (XSS) Vulnerabilities
Multiple cross-site scripting vulnerabilities in the User-ID Authentication Portal, GlobalProtect gateway/portal, and Clientless VPN features of Palo Alto Networks PAN-OS allow an unauthenticated attacker to inject and execute malicious JavaScript in user browsers. The vulnerabilities affect PAN-OS on PA-Series and VM-Series firewalls and on Panorama (virtual and M-Series). Cloud NGFW is not affected. Security risk is minimized when management interfaces and portal access are restricted to trusted internal IP addresses only.
- <parameter name="prerequisites"> <parameter name="item">Network reachability to the User-ID Authentication Portal, GlobalProtect gateway/portal, or Clientless VPN interface (typically management IP or user-accessible VPN endpoint)
Patching may require device reboot — plan for process interruption
/api/v1/advisories/a9a7da1b-e01e-45c7-a614-5a23b62ba623Get OT security insights every Tuesday
Advisory breakdowns, a weekly summary, and incident analyses for the people actually defending OT environments. Free, no account required.