XML External Entity (XXE) in PAN-OS (PAN-SA-2017-0024)

Last revised: 08/30/2017


A vulnerability exists in PAN-OS’s GlobalProtect internal and external gateway interface that could allow for XML External Entity (XXE) attack. PAN-OS does not properly parse XML input. (Ref # PAN-75688 / CVE-2017-9458)

Severity: High

Successful exploitation of this issue may allow disclosure of information, denial of service or server side request forgery.

Products Affected

PAN-OS 6.1.17 and earlier, PAN-OS 7.0.16 and earlier, PAN-OS 7.1.11 and earlier, PAN-OS 8.0.2 and earlier

Available Updates

PAN-OS 6.1.18 and later, PAN-OS 7.0.17 and later, PAN-OS 7.1.12 and later, PAN-OS 8.0.3 and later

Workarounds and Mitigations

Customers that have not configured GlobalProtect are not affected by this issue.


Palo Alto Networks would like to thank Alejandro Iacobelli and Nicolas Videla from Mercadolibre for reporting (CVE-2017-9458).