CVE-2017-15943: Palo Alto Networks PAN-OS
Medium severity, CVSS 5.3. EPSS: 1.7% chance of exploitation in the next 30 days.
The configuration file import for applications, spyware and vulnerability objects functionality in the web interface in Palo Alto Networks PAN-OS before 6.1.19, 7.0.x before 7.0.19, and 7.1.x before 7.1.14 allows remote attackers to conduct server-side request forgery (SSRF) attacks and consequently obtain sensitive information via vectors related to parsing of external entities.
Affected products
- Palo Alto Networks PAN-OS: before 6.1.19 (fixed in 6.1.19); from 7.0.0, before 7.0.19 (fixed in 7.0.19); from 7.1.0, before 7.1.14 (fixed in 7.1.14)
Published 2017-12-11. Last modified 2026-06-17.