CVE-2015-4162: Palo Alto Networks PAN-OS

Medium severity, CVSS 4.0. EPSS: 1% chance of exploitation in the next 30 days.

XML external entity (XXE) vulnerability in the management interface in PAN-OS before 5.0.16, 6.x before 6.0.8, and 6.1.x before 6.1.4 allows remote authenticated administrators to obtain sensitive information via crafted XML data.

Affected products

  • Palo Alto Networks PAN-OS: up to and including 5.0.15; version 6.0 only; version 6.0.1 only; version 6.0.2 only; version 6.0.3 only; version 6.0.4 only; …

Published 2015-06-02. Last modified 2026-06-17.