vulnerability

Palo Alto Networks PAN-SA-2016-0032: Insecure Browser API Token Generation

Severity
8
CVSS
(AV:N/AC:L/Au:N/C:C/I:N/A:N)
Published
Oct 31, 2016
Added
Oct 31, 2016
Modified
Feb 18, 2025

Description

The Palo Alto Networks firewalls API browser does not properly use the REST API tokens. In a specific scenario, an attacker could steal the authentication token and perform calls to the firewall's API. (Ref # PAN-61046/100428)

Solutions

palo-alto-networks-pan-os-upgrade-5-0palo-alto-networks-pan-os-upgrade-5-1palo-alto-networks-pan-os-upgrade-6-0palo-alto-networks-pan-os-upgrade-6-1palo-alto-networks-pan-os-upgrade-7-0palo-alto-networks-pan-os-upgrade-7-1
Title
NEW

Explore Exposure Command

Confidently identify and prioritize exposures from endpoint to cloud with full attack surface visibility and threat-aware risk context.