CVE-2016-9149: Palo Alto Networks PAN-OS

Medium severity, CVSS 6.5. EPSS: 2% chance of exploitation in the next 30 days.

The Addresses Object parser in Palo Alto Networks PAN-OS before 5.0.20, 5.1.x before 5.1.13, 6.0.x before 6.0.15, 6.1.x before 6.1.15, 7.0.x before 7.0.11, and 7.1.x before 7.1.6 mishandles single quote characters, which allows remote authenticated users to conduct XPath injection attacks via a crafted string.

Affected products

  • Palo Alto Networks PAN-OS: from 5.0.0, before 5.0.20 (fixed in 5.0.20); from 5.1.0, before 5.1.13 (fixed in 5.1.13); from 6.0.0, before 6.0.15 (fixed in 6.0.15); from 6.1.0, before 6.1.15 (fixed in 6.1.15); from 7.0.0, before 7.0.11 (fixed in 7.0.11); from 7.1.0, before 7.1.6 (fixed in 7.1.6)

Published 2016-11-19. Last modified 2026-06-17.