跳转到帖子

PAN-OS: Weak Certificate Strength in Panorama Software Leads to Sensitive Information Disclosure

recommended_posts

发布于
  • Members

PAN-OS: Weak Certificate Strength in Panorama Software Leads to Sensitive Information Disclosure

Severity
5
CVSS
(AV:N/AC:H/Au:N/C:C/I:N/A:N)
Published
04/10/2024
Created
01/08/2025
Added
01/07/2025
Modified
01/16/2025

Description

A weak (low bit strength) device certificate in Palo Alto Networks Panorama software enables an attacker to perform a meddler-in-the-middle (MitM) attack to capture encrypted traffic between the Panorama management server and the firewalls it manages. With sufficient computing resources, the attacker could break encrypted communication and expose sensitive information that is shared between the management server and the firewalls.

Solution(s)

  • palo-alto-networks-pan-os-upgrade-latest

References

  • https://attackerkb.com/topics/cve-2024-3387
  • CVE - 2024-3387
  • https://security.paloaltonetworks.com/CVE-2024-3387
  • 查看数 708
  • 已创建
  • 最后回复

参与讨论

你可立刻发布并稍后注册。 如果你有帐户,立刻登录发布帖子。
注意:你的帖子需要版主批准后才能看到。

游客
回帖…