• Creation
  • Validation
  • Communication & fix
  • Disclosure

kbl-bank.com / Palo Alto (Global-network) instance is outdated

Deleted user reported 2021-11-14

The following Palo Alto (Global-network) is publicly accessible and looks out-dated : https://80.255.163.15/global-protect/login.esp

It is critical to update to a safe version as soon as possible since multiple CVEs could allow remote attackers to DoS or achieve RCE (Remote code execution) on the device.

Reference:

IP:
80.255.163.15
Port:
443
Detected protocol:
https
Found PAN-OS web frontend
Last update: 6/2020
Version: 8.1.15
Affected by CVE-2021-3064
Found by PaloAltoPlugin 2021-11-14
IP:
80.255.163.15
Port:
443
Detected protocol:
https
Found PAN-OS web frontend
Last update: 6/2020
Version: 8.1.15
Affected by CVE-2021-3064
Found by PaloAltoPlugin 2021-11-17
IP:
80.255.163.15
Port:
443
Detected protocol:
https
Found PAN-OS web frontend
Last update: 6/2020
Version: 8.1.15
Affected by CVE-2021-3064
Found by PaloAltoPlugin 2021-11-18
Report created by deleted-user  2021-11-14
Report approved by BloodyShell  2021-11-14
New PDF report generated by system 2021-11-14
Report dispatched to ...@... by system 2021-11-14
Report dispatched to ...@... by system 2021-11-14
system commented 2021-11-14: approved shows in report

Email from: 

Dear Sender,
Please note that I will not be able to reply to your messages.
Your mail is not forwarded.

If you need assistance regarding Marketing subjects, please contact St�phane Basinski (00 352 4797 3580).

If your query concerns the Intranet Group Project, please contact Marcelo Zambrano (00 352 4797 3704).
Kind regards,

Giorgio Libotte

--------------------------------------------------------------------------------

This e-mail is intended only for the addressee named above. It does not bind the sender, except in the case of an existing written convention with the addressee. This e-mail may contain material that is confidential and privileged for the sole use of the intended recipient. Any review, reliance or distribution by others or forwarding without express permission is strictly prohibited and may be unlawful. If you are not the intended recipient, please contact the sender and delete all copies.

While reasonable precautions have been taken to ensure that this e-mail and any attachments are free from any computer virus or similar defect, no liability will be accepted in that respect. Anyone accessing this e-mail must take their own precautions as to security and virus protection.

Quintet Private Bank (Europe) S.A., 43 boulevard Royal L-2955 Luxembourg, R.C.S. Luxembourg B 6395, T +352 47 97 1

Report comment dispatched to BloodyShell by system 2021-11-14
Report comment dispatched to iampritam by system 2021-11-14
Report comment dispatched to fokoil by system 2021-11-14
Report edited by BloodyShell  2021-11-14
New PDF report generated by system 2021-11-14
Report comment 95f631 approved by BloodyShell  2021-11-14
New PDF report generated by system 2021-11-14
Report comment dispatched to zythop by system 2021-11-14
Report comment dispatched to soc@govcert.etat.lu by system 2021-11-14
system commented 2021-11-22: approved shows in report

bip! I'm a LeakIX probe.

This issue looks like it has been resolved!

New PDF report generated by system 2021-11-22
Report comment dispatched to zythop by system 2021-11-22
Report comment dispatched to soc@govcert.etat.lu by system 2021-11-22
Report marked as fixed by BloodyShell  2021-11-22
Report closed by BloodyShell  2021-11-22
New PDF report generated by system 2021-11-22
Report edited by BloodyShell  2021-11-24
New PDF report generated by system 2021-11-24
Information
Owner kbl-bank.com
Created 2021-11-14 12:41
Updated 2021-11-24 16:50
Fixed true

Contacts
s...@govcert.etat.lu

Status
Status closed
Hosting contacted false
CERT contacted false

Download report