Rewterz Threat Update –Multiple Cisco Identity Services Engine Stored Cross-Site Scripting Vulnerabilities
August 12, 2021Rewterz Threat Advisory –CVE-2021-30789 – Apple macOS Security Vulnerability
August 12, 2021Rewterz Threat Update –Multiple Cisco Identity Services Engine Stored Cross-Site Scripting Vulnerabilities
August 12, 2021Rewterz Threat Advisory –CVE-2021-30789 – Apple macOS Security Vulnerability
August 12, 2021Severity
High
Analysis Summary
CVE-2021-3047
A cryptographically weak pseudo-random number generator (PRNG) is used during authentication to the Palo Alto Networks PAN-OS web interface. This enables an authenticated attacker, with the capability to observe their own authentication secrets over a long duration on the PAN-OS appliance, to impersonate another authenticated web interface administrator’s session.
CVE-2021-3045
An OS command argument injection vulnerability in the Palo Alto Networks PAN-OS web interface enables an authenticated administrator to read any arbitrary file from the file system.
CVE-2021-3048
Certain invalid URL entries contained in an External Dynamic List (EDL) cause the Device Server daemon (devsrvr) to stop responding. This condition causes subsequent commits on the firewall to fail and prevents administrators from performing commits and configuration changes even though the firewall remains otherwise functional. If the firewall then restarts, it results in a denial-of-service (DoS) condition and the firewall stops processing traffic.
CVE-2021-3046
An improper authentication vulnerability exists in Palo Alto Networks PAN-OS software that enables a SAML authenticated attacker to impersonate any other user in the GlobalProtect Portal and GlobalProtect Gateway when they are configured to use SAML authentication.
CVE-2021-3050
An OS command injection vulnerability in the Palo Alto Networks PAN-OS web interface enables an authenticated administrator to execute arbitrary OS commands to escalate privileges.
Impact
- Data Encryption
- Command Injection
- Denial of Service
- Privilege Escalation
- Unauthorized Access
Affected Vendors
Palo Alto
Affected Products
- PAN-OS 8.1 versions earlier than PAN-OS 8.1.19
- PAN-OS 9.0 versions earlier than PAN-OS 9.0.14
- PAN-OS 9.1 versions earlier than PAN-OS 9.1.10
- PAN-OS 10.0 versions earlier than PAN-OS 10.0.4
Remediation
Refer to vendor advisory for the complete list of affected products and their respective patches.
https://security.paloaltonetworks.com/CVE-2021-3047
https://security.paloaltonetworks.com/CVE-2021-3045
https://security.paloaltonetworks.com/CVE-2021-3048