Palo Alto Security Updates – 13 April 2023

Palo Alto has released security updates to fix multiple vulnerabilities in PAN-OS and GlobalProtect App systems.

The addressed vulnerabilities could allow the attacker to delete files from the local file system, or expose the plaintext values of secrets stored in the device configuration and encrypted API keys.

Sample of the addressed vulnerabilities:

PAN-OS: Local File Deletion Vulnerability (CVE-2023-0004):

  • CVSS: 6.5
  • Attack Vector: Network
  • Attack Complexity: Low
  • Privileges Required: High
  • User Interaction: None
  • Consequences: File Manipulation
Vulnerabilities
  • CVE-2023-0004
  • CVE-2023-0005
  • CVE-2023-0006
Mitigations

The enterprise should deploy this patch as soon as the testing phase is completed.

Palo Alto Security Advisory

References