8.8
CVE-2024-0008
- EPSS 0.25%
- Veröffentlicht 14.02.2024 18:15:47
- Zuletzt bearbeitet 09.12.2024 15:18:26
- Quelle psirt@paloaltonetworks.com
- Teams Watchlist Login
- Unerledigt Login
Web sessions in the management interface in Palo Alto Networks PAN-OS software do not expire in certain situations, making it susceptible to unauthorized access.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Paloaltonetworks ≫ Pan-os Version >= 10.2.0 < 10.2.5
Paloaltonetworks ≫ Pan-os Version >= 11.0.0 < 11.0.2
Paloaltonetworks ≫ Pan-os Version >= 10.1.0 < 10.1.10
Paloaltonetworks ≫ Pan-os Version10.1.10 Update-
Paloaltonetworks ≫ Pan-os Version >= 10.0.0 < 10.0.12
Paloaltonetworks ≫ Pan-os Version10.0.12 Update-
Paloaltonetworks ≫ Pan-os Version >= 9.1.0 < 9.1.17
Paloaltonetworks ≫ Pan-os Version >= 9.0.0 < 9.0.17
Paloaltonetworks ≫ Pan-os Version9.0.17 Update-
Paloaltonetworks ≫ Pan-os Version9.0.17 Updateh1
Zu dieser CVE wurde keine CISA KEV oder CERT.AT-Warnung gefunden.
Typ | Quelle | Score | Percentile |
---|---|---|---|
EPSS | FIRST.org | 0.25% | 0.483 |
Quelle | Base Score | Exploit Score | Impact Score | Vector String |
---|---|---|---|---|
nvd@nist.gov | 8.8 | 2.8 | 5.9 |
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
|
psirt@paloaltonetworks.com | 6.6 | 0.7 | 5.9 |
CVSS:3.1/AV:P/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
|
CWE-613 Insufficient Session Expiration
According to WASC, "Insufficient Session Expiration is when a web site permits an attacker to reuse old session credentials or session IDs for authorization."