CVE Feed

    Dashboard / CVE / CVE-2021-3031

    CVE-2021-3031

    Padding bytes in Ethernet packets on PA-200, PA-220, PA-500, PA-800, PA-2000 Series, PA-3000 Series, PA-3200 Series, PA-5200 Series, and PA-7000 Series firewalls are not cleared before the data frame is created. This leaks a small amount of random information from the firewall memory into the Ethernet packets. An attacker on the same Ethernet subnet as the PAN-OS firewall is able to collect potentially sensitive information from these packets. This issue is also known as Etherleak and is detected by security scanners as CVE-2003-0001. This issue impacts: PAN-OS 8.1 version earlier than PAN-OS 8.1.18; PAN-OS 9.0 versions earlier than PAN-OS 9.0.12; PAN-OS 9.1 versions earlier than PAN-OS 9.1.5.

    Published:Jan 13, 2021
    Last Modified:Nov 21, 2024
    EPS:Jan 13, 2021
    EPSS Score:0.00075
    CVSS Score:4.3

    Affected Products

    Vendor
    Paloaltonetworks
    Product
    Pa-200
    Vendor
    Paloaltonetworks
    Product
    Pa-2020
    Vendor
    Paloaltonetworks
    Product
    Pa-2050
    Vendor
    Paloaltonetworks
    Product
    Pa-220
    Vendor
    Paloaltonetworks
    Product
    Pa-3020
    Vendor
    Paloaltonetworks
    Product
    Pa-3050
    Vendor
    Paloaltonetworks
    Product
    Pa-3060
    Vendor
    Paloaltonetworks
    Product
    Pa-3220
    Vendor
    Paloaltonetworks
    Product
    Pa-3250
    Vendor
    Paloaltonetworks
    Product
    Pa-3260
    Vendor
    Paloaltonetworks
    Product
    Pa-500
    Vendor
    Paloaltonetworks
    Product
    Pa-5200
    Vendor
    Paloaltonetworks
    Product
    Pa-800
    Vendor
    Paloaltonetworks
    Product
    Pan-os

    Exploits

    No exploit reference

    Common Attack Pattern Enumeration and Classification (CAPEC)

    Common Vulnerability Scoring System

    Attack Vector
    Network
    Adjacent
    Local
    Physical
    Privileges Required
    None
    Low
    High
    User Interaction
    None
    Required
    Scope
    Unchanged
    Changed
    Confidentiality
    None
    Low
    High
    Integrity
    None
    Low
    High
    Availability
    None
    Low
    High