PAN-OS: Administrator secrets are logged in web server logs when using the PAN-OS XML API incorrectly
Vulnerability Description
An information exposure through log file vulnerability exists in Palo Alto Networks PAN-OS software where secrets in PAN-OS XML API requests are logged in cleartext to the web server logs when the API is used incorrectly. This vulnerability applies only to PAN-OS appliances that are configured to use the PAN-OS XML API and exists only when a client includes a duplicate API parameter in API requests. Logged information includes the cleartext username, password, and API key of the administrator making the PAN-OS XML API request.
Impact Analysis
Refer to official advisory for detailed impact metrics.
Remediation
Ensure systems are updated to the latest vendor-supplied patch levels.
Am I Vulnerable?
Launch our assessment wizard to check if your infrastructure is exposed to • CVE-2021-3036
Credits & Attribution
The following person or organization is credited with identifying this vulnerability, as recorded in the NVD database:
- Palo Alto Networks thanks David Tien of Cyber Risk for discovering and reporting this issue.
More from Palo Alto Networks
View All →Affected Vendor
Palo Alto Networks
View all reports →