Palo Alto Networks PAN-OS 10.0.x / 10.2.x / 11.0.x / 8.1.x / 9.0.x / 9.1.x Vulnerability

medium Nessus Plugin ID 344799

Synopsis

The remote PAN-OS host is affected by a vulnerability

Description

The version of Palo Alto Networks PAN-OS running on the remote host is a vulnerable version of 8.1.x, 9.0.x, 9.1.x, 10.0.x, 10.2.x, or 11.0.x. It is, therefore, affected by a vulnerability.

A cross-site scripting (XSS) vulnerability in Palo Alto Networks PAN-OS software enables a malicious authenticated read-write administrator to store a JavaScript payload using the web interface. Then, when viewed by a properly authenticated administrator, the JavaScript payload executes and disguises all associated actions as performed by that unsuspecting authenticated administrator.

Tenable has extracted the preceding description block directly from the PAN-OS security advisory.

Note that Nessus has not tested for this issue but has instead relied only on the application's self-reported version number.

Solution

Upgrade to a fixed version

See Also

https://security.paloaltonetworks.com/CVE-2023-3283

Plugin Details

Severity: Medium

ID: 344799

File Name: palo_alto_CVE-2023-6789.nasl

Version: 1.1

Type: Combined

Published: 9/11/2026

Updated: 9/11/2026

Supported Sensors: Nessus

Risk Information

VPR

Risk Factor: Low

Score: 2.3

Percentile: 8.67

CVSS v2

Risk Factor: Medium

Base Score: 4.7

Temporal Score: 3.5

Vector: CVSS2#AV:N/AC:L/Au:M/C:P/I:P/A:N

CVSS Score Source: CVE-2023-6789

CVSS v3

Risk Factor: Medium

Base Score: 4.8

Temporal Score: 4.2

Vector: CVSS:3.0/AV:N/AC:L/PR:H/UI:R/S:C/C:L/I:L/A:N

Temporal Vector: CVSS:3.0/E:U/RL:O/RC:C

Vulnerability Information

CPE: cpe:/o:paloaltonetworks:pan-os

Required KB Items: Host/Palo_Alto/Firewall/Version, Host/Palo_Alto/Firewall/Full_Version, Host/Palo_Alto/Firewall/Source

Exploit Ease: No known exploits are available

Patch Publication Date: 12/13/2023

Vulnerability Publication Date: 12/13/2023

Reference Information

CVE: CVE-2023-6789

CWE: 79