CVE-2017-7945
CRITICALPalo Alto Networks PAN-OS Unauthenticated User Enumeration via GlobalProtect Login Error Messages
Title source: llmDescription
The GlobalProtect external interface in Palo Alto Networks PAN-OS before 6.1.17, 7.x before 7.0.15, 7.1.x before 7.1.9, and 8.x before 8.0.2 provides different error messages for failed login attempts depending on whether the username exists, which allows remote attackers to enumerate account names and conduct brute-force attacks via a series of requests, aka PAN-SA-2017-0014 and PAN-72769.
References (1)
Core 1
Core References
Various Sources x_refsource_confirm
https://security.paloaltonetworks.com/CVE-2017-7945
Scores
CVSS v3
9.8
EPSS
0.0044
EPSS Percentile
63.2%
Attack Vector
NETWORK
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Details
CWE
CWE-209
Status
published
Products (27)
paloaltonetworks/pan-os
7.0.0
paloaltonetworks/pan-os
7.0.1
paloaltonetworks/pan-os
7.0.2
paloaltonetworks/pan-os
7.0.3
paloaltonetworks/pan-os
7.0.4
paloaltonetworks/pan-os
7.0.5 (2 CPE variants)
paloaltonetworks/pan-os
7.0.6
paloaltonetworks/pan-os
7.0.7
paloaltonetworks/pan-os
7.0.8
paloaltonetworks/pan-os
7.0.9
... and 17 more
Published
Apr 29, 2017
Tracked Since
Feb 18, 2026