CVE-2026-0240
גבוהה 8.7
תיאור (מקור, אנגלית)
An information disclosure vulnerability in Trust Protection Foundation enables an authenticated attacker to obtain sensitive information from the server's vault. Successful exploitation of this issue allows the attacker to impersonate any user within the environment and arbitrarily modify configuration settings.
מדדים
- CVSS 3.1
-
8.7 (HIGH)
מקור הציון: NVD
CVSS:3.1/AV:A/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:N - CVSS 4.0
-
4.5 (MEDIUM)
מקור הציון: CNA
CVSS:4.0/AV:A/AC:L/AT:P/PR:L/UI:N/VC:H/VI:H/VA:N/SC:L/SI:L/SA:N/E:U/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:N/R:U/V:D/RE:M/U:Amber - EPSS — סבירות ניצול
- 0% (אחוזון 000) נכון ל-3/8/2026
- CWE
- CWE-497
מוצרים מושפעים
paloaltonetworks: trust protection foundation
קישורים
- https://security.paloaltonetworks.com/CVE-2026-0240 Vendor Advisory