{"document":{"category":"csaf_vex","csaf_version":"2.1","notes":[{"category":"summary","text":"Palo Alto Networks PSIRT provided VEX document. This document is autogenerated.","title":"HTTP Header Evasion"}],"publisher":{"category":"vendor","name":"Palo Alto Networks","namespace":"https://security.paloaltonetworks.com"},"title":"Palo Alto Networks PSIRT provided VEX document: PAN-SA-2016-0006","distribution":{"text":"Copyright © 2024 Palo Alto Networks. All rights reserved.","tlp":{"label":"CLEAR","url":"https://www.first.org/tlp/"}},"tracking":{"current_release_date":"2026-08-23T23:13:00.779Z","generator":{"date":"2026-08-23T23:13:00.779Z","engine":{"name":"Vulnogram","version":"0.0.9"}},"id":"PAN-SA-2016-0006","initial_release_date":"2016-04-18T16:00:00.000Z","revision_history":[{"number":"1","date":"2026-08-23T16:13:00.000Z","summary":"Initial release"}],"status":"final","version":"1"}},"product_tree":{"branches":[{"name":"Palo Alto Networks","category":"vendor","branches":[]}]},"vulnerabilities":[{"cve":"PAN-SA-2016-0006","product_status":{"known_affected":["PANW-PAN-OS-451","PANW-PAN-OS-436","PANW-PAN-OS-420","PANW-PAN-OS-524"],"known_not_affected":["PANW-PAN-OS-752"]},"notes":[{"category":"description","text":"An evasion was identified whereby a user could specially craft an HTTP header to evade URL filtering on Palo Alto Networks firewalls. (Ref #93838)\nThe HTTP header evasion technique can be used by a malicious insider to bypass URL filtering policy.  It is not a product vulnerability that affects the security or integrity of the firewall itself. Most legitimate web servers will not accept such incoming packets. The evasion is only possible if the destination web server does not perform basic checks on the request. Note that this evasion cannot be used to attack and penetrate a network from the outside. It can only be used by a malicious insider to evade URL filtering from the inside of the protected network.\nThis issue affects PAN-OS releases 5.0.X; 6.0.X; 6.1.X; 7.0.X and 7.1.0"}],"references":[{"category":"external","summary":"NVD - PAN-SA-2016-0006","url":"https://nvd.nist.gov/vuln/detail/PAN-SA-2016-0006"},{"category":"self","summary":"Palo Alto Networks Security Advisory PAN-SA-2016-0006","url":"https://security.paloaltonetworks.com/PAN-SA-2016-0006"}],"threats":[{"category":"impact","description":"An evasion was identified whereby a user could specially craft an HTTP header to evade URL filtering on Palo Alto Networks firewalls. (Ref #93838)\nThe HTTP header evasion technique can be used by a malicious insider to bypass URL filtering policy.  It is not a product vulnerability that affects the security or integrity of the firewall itself. Most legitimate web servers will not accept such incoming packets. The evasion is only possible if the destination web server does not perform basic checks on the request. Note that this evasion cannot be used to attack and penetrate a network from the outside. It can only be used by a malicious insider to evade URL filtering from the inside of the protected network.\nThis issue affects PAN-OS releases 5.0.X; 6.0.X; 6.1.X; 7.0.X and 7.1.0"}],"scores":[{"cvss_v3":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:L/I:L/A:N","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"LOW","userInteraction":"REQUIRED","scope":"UNCHANGED","confidentialityImpact":"LOW","integrityImpact":"LOW","availabilityImpact":"NONE","baseScore":4.6,"baseSeverity":"MEDIUM"},"products":["PANW-PAN-OS-451","PANW-PAN-OS-436","PANW-PAN-OS-420","PANW-PAN-OS-524"]}]}]}