{"document":{"category":"csaf_vex","csaf_version":"2.1","notes":[{"category":"summary","text":"Palo Alto Networks PSIRT provided VEX document. This document is autogenerated.","title":"Update Server API Exposure"}],"publisher":{"category":"vendor","name":"Palo Alto Networks","namespace":"https://security.paloaltonetworks.com"},"title":"Palo Alto Networks PSIRT provided VEX document: PAN-SA-2016-0010","distribution":{"text":"Copyright © 2024 Palo Alto Networks. All rights reserved.","tlp":{"label":"CLEAR","url":"https://www.first.org/tlp/"}},"tracking":{"current_release_date":"2026-09-17T05:32:06.421Z","generator":{"date":"2026-09-17T05:32:06.421Z","engine":{"name":"Vulnogram","version":"0.0.9"}},"id":"PAN-SA-2016-0010","initial_release_date":"2016-07-01T18:00:00.000Z","revision_history":[{"number":"1","date":"2026-09-16T22:32:06.000Z","summary":"Initial release"}],"status":"final","version":"1"}},"product_tree":{"branches":[{"name":"Palo Alto Networks","category":"vendor","branches":[]}]},"vulnerabilities":[{"cve":"PAN-SA-2016-0010","product_status":{"known_affected":["PANW-Update-server-1"]},"notes":[{"category":"description","text":"The Palo Alto Networks update server enables downloading of PAN-OS software releases and dynamic updates through a public API. Some functions of the API were inadvertently exposed to the public. \nAPI functions publicly available and exclusively used by internal workflow allowed for remote call. This did not affect Palo Alto Networks customers’ security posture, but some Palo Alto Networks update server data could be accessed.\nThis issue affects Palo Alto Networks update server"}],"references":[{"category":"external","summary":"NVD - PAN-SA-2016-0010","url":"https://nvd.nist.gov/vuln/detail/PAN-SA-2016-0010"},{"category":"self","summary":"Palo Alto Networks Security Advisory PAN-SA-2016-0010","url":"https://security.paloaltonetworks.com/PAN-SA-2016-0010"}],"threats":[{"category":"impact","description":"The Palo Alto Networks update server enables downloading of PAN-OS software releases and dynamic updates through a public API. Some functions of the API were inadvertently exposed to the public. \nAPI functions publicly available and exclusively used by internal workflow allowed for remote call. This did not affect Palo Alto Networks customers’ security posture, but some Palo Alto Networks update server data could be accessed.\nThis issue affects Palo Alto Networks update server"}],"scores":[{"cvss_v3":{"version":"3.1","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"NONE","integrityImpact":"NONE","availabilityImpact":"NONE","vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:N","baseScore":0,"baseSeverity":"NONE"},"products":["PANW-Update-server-1"]}]}]}