Loading...
Loading...
Known affected versions were inferred from fixed-version data and were not explicitly confirmed by the vendor: 8.1.19, 9.1.9
The earliest recollection of this bug is traced back to PAN-OS 8.1.20 - July 22, 2025. This bug is fixed in PAN-OS versions 9.1.10, 8.1.20. A fix was made to address an improper restriction of XML external identity (XXE) reference in the PAN-OS web interface that enabled an authenticated administrator to read any arbitrary file from the file system and send a specifically crafted request to the firewall that caused the service to crash ( CVE-2021-3055 ). For more information: https://docs.paloaltonetworks.com/pan-os/8-1/pan-os-release-notes/pan-os-8-1-addressed-issues/pan-os-8-1-20-addressed-issues https://docs.paloaltonetworks.com/pan-os/9-1/pan-os-release-notes/pan-os-9-1-addressed-issues/pan-os-9-1-10-addressed-issues
Palo Alto Networks Integration
Learn more about where this data comes from
BugZero Plan
Streamline upgrades with automated vendor bug scrubs
BugZero Prevent
Wish you caught this bug sooner? Get proactive today.