Palo Alto Networks User-ID Agent < 7.0.4 TLS-Secured API Invocation Credential Disclosure (PAN-SA-2016-0007)
Medium Nessus Plugin ID 91673
SynopsisThe Palo Alto Networks User-ID agent installed on the remote host is affected by a credential disclosure vulnerability.
DescriptionThe version of Palo Alto Networks User-ID agent installed on the remote Windows host is prior to 7.0.4. It is, therefore, affected by a flaw that allows a TLS-secured API call to return encrypted credentials to the domain account configured on the User-ID agent, which has read-only rights for Security Event Logs on Domain Controllers. An authenticated, remote attacker with access to the User-ID agent Service TCP port can exploit this to gain access to credential information.
SolutionUpgrade to Palo Alto Networks User-ID agent version 7.0.4