Vulnerability Description
The PAN-OS management web interface in PAN-OS 7.1.21 and earlier, PAN-OS 8.0.14 and earlier, and PAN-OS 8.1.5 and earlier, may allow an unauthenticated attacker to inject arbitrary JavaScript or HTML.
CVSS Score
MEDIUM
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Paloaltonetworks | Pan-Os | >= 7.1.0, < 7.1.22 |
Related Weaknesses (CWE)
References
- http://www.securityfocus.com/bid/106750Third Party AdvisoryVDB Entry
- https://security.paloaltonetworks.com/CVE-2019-1566Vendor Advisory
- https://www.purplemet.com/blog/palo-alto-firewall-multiple-xss-vulnerabilitiesThird Party Advisory
- http://www.securityfocus.com/bid/106750Third Party AdvisoryVDB Entry
- https://security.paloaltonetworks.com/CVE-2019-1566Vendor Advisory
- https://www.purplemet.com/blog/palo-alto-firewall-multiple-xss-vulnerabilitiesThird Party Advisory
FAQ
What is CVE-2019-1566?
CVE-2019-1566 is a vulnerability with a CVSS score of 6.1 (MEDIUM). The PAN-OS management web interface in PAN-OS 7.1.21 and earlier, PAN-OS 8.0.14 and earlier, and PAN-OS 8.1.5 and earlier, may allow an unauthenticated attacker to inject arbitrary JavaScript or HTML.
How severe is CVE-2019-1566?
CVE-2019-1566 has been rated MEDIUM with a CVSS base score of 6.1/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2019-1566?
Check the references section above for vendor advisories and patch information. Affected products include: Paloaltonetworks Pan-Os.