High severity8.8NVD Advisory· Published Jul 16, 2019· Updated Jun 17, 2026
CVE-2019-1575
CVE-2019-1575
Description
Information disclosure in PAN-OS 7.1.23 and earlier, PAN-OS 8.0.18 and earlier, PAN-OS 8.1.8-h4 and earlier, and PAN-OS 9.0.2 and earlier may allow for an authenticated user with read-only privileges to extract the API key of the device and/or the username/password from the XML API (in PAN-OS) and possibly escalate privileges granted to them.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected products
5- Palo Alto/Palo Alto Networks PAN-OSv5Range: PAN-OS 7.1.23 and earlier
<=7.1.23, <=8.0.18, <=8.1.8-h4, <=9.0.2+ 3 more
- (no CPE)range: <=7.1.23, <=8.0.18, <=8.1.8-h4, <=9.0.2
- cpe:2.3:o:paloaltonetworks:pan-os:*:*:*:*:*:*:*:*range: <7.1.24
- cpe:2.3:o:paloaltonetworks:pan-os:8.1.8:-:*:*:*:*:*:*
- cpe:2.3:o:paloaltonetworks:pan-os:8.1.8:h4:*:*:*:*:*:*
Patches
Vulnerability mechanics
References
2- www.securityfocus.com/bid/109176nvdThird Party AdvisoryVDB Entry
- security.paloaltonetworks.com/CVE-2019-1575nvdVendor Advisory
News mentions
0No linked articles in our index yet.