CVE-2017-17841

Description

Palo Alto Networks PAN-OS 6.1, 7.1, and 8.0.x before 8.0.7, when an interface implements SSL decryption with RSA enabled or hosts a GlobalProtect portal or gateway, might allow remote attackers to decrypt TLS ciphertext data by leveraging a Bleichenbacher RSA padding oracle, aka a ROBOT attack.

Risk Information

Base Score
5.9
MODERATE
Vector
CVSS:3.0/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:N
EPSS Score
Exploitation Probability
1.46

Associated Vulnerability

VulnerabilityOS Platform
Multiple Vulnerabilities affected in pan-os 8.0.5NCM
Multiple Vulnerabilities affected in pan-os 8.0.4-h2NCM
Multiple Vulnerabilities affected in pan-os 8.0.4NCM
Multiple Vulnerabilities affected in pan-os 8.0.3-h4NCM
Multiple Vulnerabilities affected in pan-os 8.0.3NCM
Multiple Vulnerabilities affected in pan-os 7.1.13NCM
Multiple Vulnerabilities affected in pan-os 8.0.6-h3NCM
Multiple Vulnerabilities affected in pan-os 8.0.6NCM
Multiple Vulnerabilities affected in pan-os 7.1.5NCM
Multiple Vulnerabilities affected in pan-os 7.1.4-h2NCM
Multiple Vulnerabilities affected in pan-os 7.1.4NCM
Multiple Vulnerabilities affected in pan-os 7.1.3NCM
Multiple Vulnerabilities affected in pan-os 7.1.2NCM
Multiple Vulnerabilities affected in pan-os 7.1.1NCM
Multiple Vulnerabilities affected in pan-os 7.1.0NCM
Multiple Vulnerabilities affected in pan-os 6.1.0NCM
Multiple Vulnerabilities affected in pan-os 7.1.14NCM
Multiple Vulnerabilities affected in pan-os 7.1.11NCM
Multiple Vulnerabilities affected in pan-os 7.1.10NCM
Multiple Vulnerabilities affected in pan-os 7.1.9-h4NCM
Multiple Vulnerabilities affected in pan-os 7.1.9NCM
Multiple Vulnerabilities affected in pan-os 7.1.8NCM
Multiple Vulnerabilities affected in pan-os 7.1.7NCM
Multiple Vulnerabilities affected in pan-os 7.1.6NCM
Multiple Vulnerabilities affected in pan-os 8.0.2NCM
Multiple Vulnerabilities affected in pan-os 8.0.1NCM
Multiple Vulnerabilities affected in pan-os 8.0.0NCM
Multiple Vulnerabilities affected in pan-os 7.1.12NCM
CVE-2017-17841NCM

Patch Details

No records found

References

https://nvd.nist.gov/vuln/detail/CVE-2023-1234
https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2023-1234