What the vendor says is affected
- Cloud NGFW
- PAN-OS
- Prisma Access
- PAN-OS 12.1
- PAN-OS 11.2
- PAN-OS 11.1
- PAN-OS 10.2
- Prisma Access 11.2
- Prisma Access 10.2
Versions the vendor lists as fixed
- Cloud NGFW All on AWS, All on Azure unless you have been contacted by Palo Alto Networks
- PAN-OS 12.1 >= 12.1.4-h8, >= 12.1.7-h2, >= 12.1.8
- PAN-OS 11.2 >= 11.2.4-h20, >= 11.2.7-h18, >= 11.2.10-h12, >= 11.2.13
- PAN-OS 11.1 >= 11.1.4-h35, >= 11.1.6-h35, >= 11.1.7-h8, >= 11.1.10-h30, >= 11.1.13-h9, >= 11.1.16
- PAN-OS 10.2 >= 10.2.7-h36, >= 10.2.10-h39, >= 10.2.13-h23, >= 10.2.16-h9, >= 10.2.18-h8
- Prisma Access 11.2 >= 11.2.7-h18*
- Prisma Access 10.2 >= 10.2.10-h39*
What the vendor recommends
VERSION MINOR VERSION SUGGESTED SOLUTION Cloud NGFW No action needed. PAN-OS 12.1 12.1.5 through 12.1.7-h* Upgrade to 12.1.7-h2 or 12.1.8 or later. 12.1.2 through 12.1.4-h* Upgrade to 12.1.4-h8 or 12.1.8 or later. PAN-OS 11.2 11.2.11 through 11.2.12 Upgrade to 11.2.13 or later. 11.2.8 through 11.2.10-h* Upgrade to 11.2.10-h12 or 11.2.13 or later. 11.2.5 through 11.2.7-h* Upgrade to 11.2.7-h18 or 11.2.13 or later. 11.2.0 through 11.2.4-h* Upgrade to 11.2.4-h20 or 11.2.13 or later. PAN-OS 11.1 11.1.14 through 11.1.15 Upgrade to 11.1.16 or later. 11.1.11 through 11.1.13-h* Upgrade to 11.1.13-h9 or 11.1.16 or later. 11.1.8 through 11.1.10-h* Upgrade to 11.1.10-h30 or 11.1.16 or later. 11.1.7 through 11.1.7-h* Upgrade to 11.1.7-h8 or 11.1.16 or later. 11.1.5 through 11.1.6-h* Upgrade to 11.1.6-h35 or 11.1.16 or later. 11.1.0 through 11.1.4-h* Upgrade to 11.1.4-h35 or 11.1.16 or later. PAN-OS 10.2 10.2.17 through 10.2.18-h* Upgrade to 10.2.18-h8 or later. 10.2.14 through 10.2.16-h* Upgrade to 10.2.16-h9 or later. 10.2.11 through 10.2.13-h* Upgrade to 10.2.13-h23 or later. 10.2.8 through 10.2.10-h* Upgrade to 10.2.10-h39 or later. 10.2.0 through 10.2.7-h* Upgrade to 10.2.7-h36 or later. All older Upgrade to a supported fixed version. unsupported PAN-OS versions Prisma Access 11.2 11.2.0 through 11.2.7 Upgrade to 11.2.7-h18 or later.* Prisma Access 10.2 10.2.0 through 10.2.10 Upgrade to 10.2.10-h39 or later.* * See the note under Product Status for information regarding Prisma Access upgrades.
Review the complete instructions on the vendor's siteWhat changed in later vendor updates
SecurityAlert records field-level changes from the point we begin following a bulletin. Earlier vendor changes may not have a field-by-field record.
- Added affected products: Prisma Access 10.2, Prisma Access 11.2.
- Removed affected products: Prisma Access 10.2.0, Prisma Access 11.2.0.
- Added fixed versions: Prisma Access 10.2 >= 10.2.10-h39*, Prisma Access 11.2 >= 11.2.7-h18*.
- Removed fixed versions: Prisma Access 10.2.0 >= 10.2.10-h39*, Prisma Access 11.2.0 >= 11.2.7-h18*.
- The vendor changed its remediation guidance.
When this advisory changed
- Published by Palo Alto Networks
The publication date reported by the vendor.
- Added to SecurityAlert
We collected the advisory from the official source.
- Confirmed at the source
Our collector saw this advisory during a later source check.