CVE-2017-5584

Cross-site scripting (XSS) vulnerability in the Management Web Interface in Palo Alto Networks PAN-OS 5.1, 6.x before 6.1.16, 7.0.x before 7.0.13, and 7.1.x before 7.1.8 allows remote authenticated users to inject arbitrary web script or HTML via unspecified vectors.
Cross-site Scripting
ProviderTypeBase ScoreAtk. VectorAtk. ComplexityPriv. RequiredVector
NISTNIST
5.4 MEDIUM
NETWORK
LOW
LOW
CVSS:3.0/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N
mitreCNA
---
---
CVEADP
---
---
Base Score
CVSS 3.x
EPSS Score
Percentile: 43%
VendorProductVersion
paloaltonetworkspan-os
5.1
paloaltonetworkspan-os
6.0
paloaltonetworkspan-os
6.0.1
paloaltonetworkspan-os
6.0.2
paloaltonetworkspan-os
6.0.3
paloaltonetworkspan-os
6.0.4
paloaltonetworkspan-os
6.0.5
paloaltonetworkspan-os
6.0.6
paloaltonetworkspan-os
6.0.7
paloaltonetworkspan-os
6.0.8
paloaltonetworkspan-os
6.0.9
paloaltonetworkspan-os
6.0.10
paloaltonetworkspan-os
6.0.11
paloaltonetworkspan-os
6.0.12
paloaltonetworkspan-os
6.1.0
paloaltonetworkspan-os
6.1.1
paloaltonetworkspan-os
6.1.2
paloaltonetworkspan-os
6.1.3
paloaltonetworkspan-os
6.1.4
paloaltonetworkspan-os
6.1.5
paloaltonetworkspan-os
6.1.6
paloaltonetworkspan-os
6.1.7
paloaltonetworkspan-os
6.1.8
paloaltonetworkspan-os
6.1.9
paloaltonetworkspan-os
6.1.10
paloaltonetworkspan-os
6.1.11
paloaltonetworkspan-os
6.1.12
paloaltonetworkspan-os
6.1.13
paloaltonetworkspan-os
6.1.14
paloaltonetworkspan-os
6.1.15
paloaltonetworkspan-os
7.0.1
paloaltonetworkspan-os
7.0.2
paloaltonetworkspan-os
7.0.3
paloaltonetworkspan-os
7.0.4
paloaltonetworkspan-os
7.0.5
paloaltonetworkspan-os
7.0.5-h2
paloaltonetworkspan-os
7.0.6
paloaltonetworkspan-os
7.0.7
paloaltonetworkspan-os
7.0.8
paloaltonetworkspan-os
7.0.9
paloaltonetworkspan-os
7.0.10
paloaltonetworkspan-os
7.0.11
paloaltonetworkspan-os
7.0.12
paloaltonetworkspan-os
7.1.0
paloaltonetworkspan-os
7.1.1
paloaltonetworkspan-os
7.1.2
paloaltonetworkspan-os
7.1.3
paloaltonetworkspan-os
7.1.4
paloaltonetworkspan-os
7.1.4-h2
paloaltonetworkspan-os
7.1.5
paloaltonetworkspan-os
7.1.6
paloaltonetworkspan-os
7.1.7
𝑥
= Vulnerable software versions