cvedb.io
CVE-2017-7945
CRITICAL · CVSS 9.8
EPSS exploitation probability: 0%
Published 2017-04-29T00:59:00.197 · Last modified 2026-06-17T01:25:31.837

Summary

The GlobalProtect external interface in Palo Alto Networks PAN-OS before 6.1.17, 7.x before 7.0.15, 7.1.x before 7.1.9, and 8.x before 8.0.2 provides different error messages for failed login attempts depending on whether the username exists, which allows remote attackers to enumerate account names and conduct brute-force attacks via a series of requests, aka PAN-SA-2017-0014 and PAN-72769.

Affected products

paloaltonetworks — pan-os

Does this affect you?

Add your gear to cvedb and we'll alert you only when paloaltonetworks ships something exploited.

Check my exposure →

References

This product uses data from the NVD API but is not endorsed or certified by the NVD. Informational only; not professional security advice.