CVE-2017-7945

CRITICAL

Palo Alto Networks PAN-OS Unauthenticated User Enumeration via GlobalProtect Login Error Messages

Title source: llm
STIX 2.1

Description

The GlobalProtect external interface in Palo Alto Networks PAN-OS before 6.1.17, 7.x before 7.0.15, 7.1.x before 7.1.9, and 8.x before 8.0.2 provides different error messages for failed login attempts depending on whether the username exists, which allows remote attackers to enumerate account names and conduct brute-force attacks via a series of requests, aka PAN-SA-2017-0014 and PAN-72769.

References (1)

Core 1
Core References
Various Sources x_refsource_confirm
https://security.paloaltonetworks.com/CVE-2017-7945

Scores

CVSS v3 9.8
EPSS 0.0044
EPSS Percentile 63.2%
Attack Vector NETWORK
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Details

CWE
CWE-209
Status published
Products (27)
paloaltonetworks/pan-os 7.0.0
paloaltonetworks/pan-os 7.0.1
paloaltonetworks/pan-os 7.0.2
paloaltonetworks/pan-os 7.0.3
paloaltonetworks/pan-os 7.0.4
paloaltonetworks/pan-os 7.0.5 (2 CPE variants)
paloaltonetworks/pan-os 7.0.6
paloaltonetworks/pan-os 7.0.7
paloaltonetworks/pan-os 7.0.8
paloaltonetworks/pan-os 7.0.9
... and 17 more
Published Apr 29, 2017
Tracked Since Feb 18, 2026