{"document":{"category":"csaf_vex","csaf_version":"2.1","notes":[{"category":"summary","text":"Palo Alto Networks PSIRT provided VEX document. This document is autogenerated.","title":"PAN-OS API denial of service"}],"publisher":{"category":"vendor","name":"Palo Alto Networks","namespace":"https://security.paloaltonetworks.com"},"title":"Palo Alto Networks PSIRT provided VEX document: PAN-SA-2016-0008","distribution":{"text":"Copyright © 2024 Palo Alto Networks. All rights reserved.","tlp":{"label":"CLEAR","url":"https://www.first.org/tlp/"}},"tracking":{"current_release_date":"2026-09-27T20:49:58.053Z","generator":{"date":"2026-09-27T20:49:58.053Z","engine":{"name":"Vulnogram","version":"0.0.9"}},"id":"PAN-SA-2016-0008","initial_release_date":"2016-06-27T17:30:00.000Z","revision_history":[{"number":"1","date":"2026-09-27T13:49:58.000Z","summary":"Initial release"}],"status":"final","version":"1"}},"product_tree":{"branches":[{"name":"Palo Alto Networks","category":"vendor","branches":[{"name":"PAN-OS","category":"product_name","branches":[{"category":"product_version_range","name":"vers:generic/PAN-OS<7.0.8","product":{"name":"Palo Alto Networks PAN-OS","product_id":"PANW-PAN-OS-771"}},{"category":"product_version_range","name":"vers:generic/PAN-OS>=7.0.8","product":{"name":"Palo Alto Networks PAN-OS","product_id":"PANW-PAN-OS-771"}}]}]}]},"vulnerabilities":[{"cve":"PAN-SA-2016-0008","product_status":{"fixed":["PANW-PAN-OS-771"],"known_affected":["PANW-PAN-OS-771"]},"notes":[{"category":"description","text":"Palo Alto Networks firewalls offer an API to query and modify the configuration of the device. While access to this API is protected by the use of an API key, an issue was recently identified leading to a potential unauthenticated denial of service attack. (Ref #91728)\nThe API is hosted on a dedicated management interface and, while this issue can result in a DoS attack of the API, it doesn’t compromise the security functionality of the device.\nThis issue affects PAN-OS 7.0.1 to PAN-OS 7.0.7"}],"references":[{"category":"external","summary":"NVD - PAN-SA-2016-0008","url":"https://nvd.nist.gov/vuln/detail/PAN-SA-2016-0008"},{"category":"self","summary":"Palo Alto Networks Security Advisory PAN-SA-2016-0008","url":"https://security.paloaltonetworks.com/PAN-SA-2016-0008"}],"threats":[{"category":"impact","description":"Palo Alto Networks firewalls offer an API to query and modify the configuration of the device. While access to this API is protected by the use of an API key, an issue was recently identified leading to a potential unauthenticated denial of service attack. (Ref #91728)\nThe API is hosted on a dedicated management interface and, while this issue can result in a DoS attack of the API, it doesn’t compromise the security functionality of the device.\nThis issue affects PAN-OS 7.0.1 to PAN-OS 7.0.7"}],"scores":[{"cvss_v3":{"version":"3.1","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"NONE","integrityImpact":"NONE","availabilityImpact":"LOW","baseSeverity":"MEDIUM","baseScore":5.3,"vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L"},"products":["PANW-PAN-OS-771"]}]}]}