← Back

CVE-2021-3031

nvd nist
Published: Jan 13, 2021Modified: Nov 21, 2024

JSON object

Loading...
4.3
Vector
CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N
Exploitability: 2.8 / Impact: 1.4
Source: psirt@paloaltonetworks.com (Secondary)

Description

Padding bytes in Ethernet packets on PA-200, PA-220, PA-500, PA-800, PA-2000 Series, PA-3000 Series, PA-3200 Series, PA-5200 Series, and PA-7000 Series firewalls are not cleared before the data frame is created. This leaks a small amount of random information from the firewall memory into the Ethernet packets. An attacker on the same Ethernet subnet as the PAN-OS firewall is able to collect potentially sensitive information from these packets. This issue is also known as Etherleak and is detected by security scanners as CVE-2003-0001. This issue impacts: PAN-OS 8.1 version earlier than PAN-OS 8.1.18; PAN-OS 9.0 versions earlier than PAN-OS 9.0.12; PAN-OS 9.1 versions earlier than PAN-OS 9.1.5.

Affected (3)

Pan Os
Configuration A
3 vulnerable · 13 platform
Vulnerable SoftwareAffected Versions
Paloaltonetworks
From 8.1.0 to 8.1.18
From 9.0.0 to 9.0.12
From 9.1.0 to 9.1.5
Running on/withPlatform Versions
Paloaltonetworks
Pa 200
All versions
Paloaltonetworks
Pa 2020
All versions
Paloaltonetworks
Pa 2050
All versions
Paloaltonetworks
Pa 220
All versions
Paloaltonetworks
Pa 3020
All versions
Paloaltonetworks
Pa 3050
All versions
Paloaltonetworks
Pa 3060
All versions
Paloaltonetworks
Pa 3220
All versions
Paloaltonetworks
Pa 3250
All versions
Paloaltonetworks
Pa 3260
All versions
Paloaltonetworks
Pa 500
All versions
Paloaltonetworks
Pa 5200
All versions
Paloaltonetworks
Pa 800
All versions

References (2)

Source: psirt@paloaltonetworks.com
Vendor Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Vendor Advisory

Timeline

No history available yet.