漏洞描述
PAN-OS management web interface is vulnerable to reflected cross-site scripting. A remote attacker able to convince an administrator with an active authenticated session on the firewall management interface to click on a crafted link to that management web interface could potentially execute arbitrary JavaScript code in the administrator's browser and perform administrative actions. This issue impacts: PAN-OS 8.1 versions earlier than PAN-OS 8.1.16; PAN-OS 9.0 versions earlier than PAN-OS 9.0.9.
影响产品
修复建议
建议关注厂商安全公告,及时升级至已修复版本,并结合实际资产暴露情况采取缓解措施。
参考链接
swarm.ptsecurity.comhttps://swarm.ptsecurity.com/swarm-of-palo-alto-pan-os-vulnerabilities/↗security.paloaltonetworks.comhttps://security.paloaltonetworks.com/CVE-2020-2036↗nvd.nist.govhttps://nvd.nist.gov/vuln/detail/CVE-2020-2036↗github.comhttps://github.com/404notf0und/CVE-Flow↗github.comhttps://github.com/ARPSyndicate/kenzer-templates↗