MEDIUM · 4.3

CVE-2021-3031

Padding bytes in Ethernet packets on PA-200, PA-220, PA-500, PA-800, PA-2000 Series, PA-3000 Series, PA-3200 Series, PA-5200 Series, and PA-7000 Series firewalls are not cleared before the data frame ...

Vulnerability Description

Padding bytes in Ethernet packets on PA-200, PA-220, PA-500, PA-800, PA-2000 Series, PA-3000 Series, PA-3200 Series, PA-5200 Series, and PA-7000 Series firewalls are not cleared before the data frame is created. This leaks a small amount of random information from the firewall memory into the Ethernet packets. An attacker on the same Ethernet subnet as the PAN-OS firewall is able to collect potentially sensitive information from these packets. This issue is also known as Etherleak and is detected by security scanners as CVE-2003-0001. This issue impacts: PAN-OS 8.1 version earlier than PAN-OS 8.1.18; PAN-OS 9.0 versions earlier than PAN-OS 9.0.12; PAN-OS 9.1 versions earlier than PAN-OS 9.1.5.

CVSS Score

4.3

MEDIUM

CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N
Attack Vector
ADJACENT_NETWORK
Attack Complexity
LOW
Privileges Required
NONE
User Interaction
NONE
Scope
UNCHANGED
Confidentiality
LOW
Integrity
NONE
Availability
NONE

Affected Products

VendorProductVersions
PaloaltonetworksPan-Os>= 8.1.0, < 8.1.18
PaloaltonetworksPa-200-
PaloaltonetworksPa-2020-
PaloaltonetworksPa-2050-
PaloaltonetworksPa-220-
PaloaltonetworksPa-3020-
PaloaltonetworksPa-3050-
PaloaltonetworksPa-3060-
PaloaltonetworksPa-3220-
PaloaltonetworksPa-3250-
PaloaltonetworksPa-3260-
PaloaltonetworksPa-500-
PaloaltonetworksPa-5200-
PaloaltonetworksPa-800-

Related Weaknesses (CWE)

References

FAQ

What is CVE-2021-3031?

CVE-2021-3031 is a vulnerability with a CVSS score of 4.3 (MEDIUM). Padding bytes in Ethernet packets on PA-200, PA-220, PA-500, PA-800, PA-2000 Series, PA-3000 Series, PA-3200 Series, PA-5200 Series, and PA-7000 Series firewalls are not cleared before the data frame ...

How severe is CVE-2021-3031?

CVE-2021-3031 has been rated MEDIUM with a CVSS base score of 4.3/10. Review the CVSS metrics above for detailed severity breakdown.

Is there a patch for CVE-2021-3031?

Check the references section above for vendor advisories and patch information. Affected products include: Paloaltonetworks Pan-Os, Paloaltonetworks Pa-200, Paloaltonetworks Pa-2020, Paloaltonetworks Pa-2050, Paloaltonetworks Pa-220.