PAN-OS: Server-Side Request Forgery Vulnerability in Management Web Interface
A server-side request forgery (SSRF) vulnerability in PAN-OS allows an authenticated administrator with network access to the management web interface to make unauthorized requests from the firewall to internal services. This could allow an attacker with compromised admin credentials to access internal systems or trigger unauthorized actions. The risk is significantly reduced if the management interface is restricted to only trusted internal IP addresses. Panorama, Cloud NGFW, and Prisma Access are not impacted.
- Valid administrator credentials for the PAN-OS management interface
- Network access to the management web interface (port 443 or custom port)
- The management interface must be accessible (not restricted to trusted internal IPs only)
Patching may require device reboot — plan for process interruption
/api/v1/advisories/8eeec10a-f8e5-47b5-80d6-54764a430f8eGet OT security insights every Tuesday
Advisory breakdowns, a weekly summary, and incident analyses for the people actually defending OT environments. Free, no account required.