Palo Alto Networks PAN-OS < 4.0.9 / 4.1.x < 4.1.3 Information Disclosure

This script is Copyright (C) 2014-2016 Tenable Network Security, Inc.


Synopsis :

The remote host is affected by an information disclosure
vulnerability.

Description :

The remote host is running a version of Palo Alto Networks PAN-OS
prior to 4.0.9 / 4.1.3. It is, therefore, affected by an information
disclosure vulnerability due to LDAP bind passwords being logged in
plaintext when using default logging settings.

Note that the 3.1 branch is not affected by this vulnerability.

See also :

https://securityadvisories.paloaltonetworks.com/Home/Detail/7

Solution :

Upgrade to PAN-OS version 4.0.9 / 4.1.3 or later.

Risk factor :

Medium / CVSS Base Score : 6.5
(CVSS2#AV:N/AC:L/Au:S/C:P/I:P/A:P)
CVSS Temporal Score : 5.7
(CVSS2#E:ND/RL:OF/RC:C)
Public Exploit Available : true

Family: Palo Alto Local Security Checks

Nessus Plugin ID: 72822 ()

Bugtraq ID: 62132

CVE ID: CVE-2012-6596

Ready to Scan Unlimited IPs & Run Compliance Checks?

Upgrade to Nessus Professional today!

Buy Now

Combine the Power of Nessus with the Ease of Cloud

Start your free Nessus Cloud trial now!

Begin Free Trial