7.5

CVE-2026-4761

Unnecessary permissions on private keys of certificates installed by Network and Security Wizard

When a certificate and its private key are installed in the Windows machine certificate store using Network and Security tool, access rights to the private key are unnecessarily granted to the operator group.
  *  Installations based on Panorama Suite 2025 (25.00.004) are vulnerable unless update PS-2500-00-0357 (or higher) is installed
  *  Installations based on Panorama Suite 2025 Updated Dec. 25 (25.10.007) are not vulnerable


Please refer to security bulletin BS-036, available on the Panorama CSIRT website: https://my.codra.net/en-gb/csirt.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Codra ≫ Panorama Com Version 25.00.004
Codra ≫ Panorama E2 Version 25.00.004
Codra ≫ Panorama H2 Version 25.00.004
Zu dieser CVE wurde keine Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 0.12% 0.023
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
NIST 7.5 3.9 3.6
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
30aa36b7-a224-4bc9-b7d3-abea20aa4887 3.3 0 0
CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:H/VI:N/VA:N/SC:H/SI:N/SA:N/E:U/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:Amber
CWE-732 Incorrect Permission Assignment for Critical Resource

The product specifies permissions for a security-critical resource in a way that allows that resource to be read or modified by unintended actors.

https://my.codra.net/api/csirt/download?resourceId=1469&fileType=FichierPDF
Vendor Advisory