Loading...
Loading...
Known affected versions were inferred from fixed-version data and were not explicitly confirmed by the vendor: 8.1.15-h3, 9.1.3-h1
The earliest recollection of this bug is traced back to PAN-OS 8.1.16 - July 22, 2025. This bug is fixed in PAN-OS versions 8.1.16, 9.1.4. A fix was made to address a vulnerability involving information exposure through log files where sensitive fields were recorded in the configuration log without masking on PAN-OS software when the after-change-detail custom syslog field was enabled for configuration logs and the sensitive field appeared multiple times in one log entry. The first instance of the sensitive field was masked but subsequent instances were left in clear text ( CVE-2020-2043 ). For more information: https://docs.paloaltonetworks.com/pan-os/8-1/pan-os-release-notes/pan-os-8-1-addressed-issues/pan-os-8-1-16-addressed-issues https://docs.paloaltonetworks.com/pan-os/9-1/pan-os-release-notes/pan-os-9-1-addressed-issues/pan-os-9-1-4-addressed-issues
Palo Alto Networks Integration
Learn more about where this data comes from
BugZero Plan
Streamline upgrades with automated vendor bug scrubs
BugZero Prevent
Wish you caught this bug sooner? Get proactive today.