PAN-SA-2017-0010 - INFORMATION DISCLOSURE IN THE MANAGEMENT WEB INTERFACE

cancel
Showing results for 
Show  only  | Search instead for 
Did you mean: 
Announcements
Please sign in to see details of an important advisory in our Customer Advisories area.

PAN-SA-2017-0010 - INFORMATION DISCLOSURE IN THE MANAGEMENT WEB INTERFACE

L0 Member

Hello

 

I detected a bug PAN-SA-2017-0010 - INFORMATION DISCLOSURE IN THE MANAGEMENT WEB INTERFACE in the environment palo alto that I support . would you give me some recommendation/workaround ?

3 REPLIES 3

Cyber Elite
Cyber Elite

Update to 7.1.9 or higher. 

Limit the management interface to only those IPs that actually need it. 

The attacker needs to be authenticated in the management interface, so don't give people access that you don't trust. 

Restrict access to a set time schedule. 

Could you provide me the appropiate steps to carry out the recommendations?

@Diego.Montoya,

Access to the management IP can be restricted by clicking on the gear icon on the management interface settings on the Devices Mangement settings like pictured below. Capture.PNG

 

You could setup an access schedule as long as your management network traffic traverses your firewall and requires that your security policy allowing access to that IP address gets assigned a Schedule to limit the times that the management network is allowed. If you put access on a schedule I would recommend leaving your Network Operations computers off of this scheduled access policy so that they can work on the device whenever needed.

 

If you have management enabled on your actual interfaces and not your management interface then you can still restrict that access to set IP addresses; you just need to modify your Interface Mgmt profile to include listed 'Permitted IP Addresses' so that it doesn't allow everything like it does by default.

 

Hope that helps.  

 

  • 1714 Views
  • 3 replies
  • 0 Likes
Like what you see?

Show your appreciation!

Click Like if a post is helpful to you or if you just want to show your support.

Click Accept as Solution to acknowledge that the answer to your question has been provided.

The button appears next to the replies on topics you’ve started. The member who gave the solution and all future visitors to this topic will appreciate it!

These simple actions take just seconds of your time, but go a long way in showing appreciation for community members and the LIVEcommunity as a whole!

The LIVEcommunity thanks you for your participation!