Palo Alto Networks exposes customer support cases and attachments
By MYBRANDBOOK
A bug in the support dashboard of Palo Alto Networks (PAN), a leading provider of cybersecurity and networking products and firewalls, exposed thousands of customer support tickets to an unauthorized individual.
The information included names and (business) contact information of the person creating support tickets, conversations between Palo Alto Networks staff members and the customer. The company said it has now fixed the issue.
A misconfiguration in the support system of Palo Alto Networks allowed sensitive information disclosure, letting a customer access private support tickets from other companies. A PAN customer discovered the issue this month and reported it to Palo Alto Networks staff.
Some of these support cases had file attachments such as firewall logs, configuration dumps, network security group (NSG) layouts, images of error messages, and similar internal files shared by customers with Palo Alto Networks for troubleshooting purposes.
Some other information exposed in the support tickets included contact name, title, email address and phone number of the customer creating the tickets, contents of conversations between PAN support staff and customers, PAN Product serial number and model and case numbers, subject line, and request severity.
PAN said that no data was downloaded and implies that the scope of the leak remained limited to just one customer. However, the bug fix took approximately eight days, after which the customer's access to the 1,900 unrelated tickets was revoked.
A Palo Alto Networks spokesperson said, “We were notified of an issue that allowed an authorized customer to view a small subset of support cases, which they typically would not be able to view. We immediately initiated an investigation and identified it was due to a permission misconfiguration error in a support system. Our analysis confirmed no data was downloaded or altered, and the issue was immediately remediated.”
Legal Battle Over IT Act Intensifies Amid Musk’s India Plans
The outcome of the legal dispute between X Corp and the Indian government c...
Wipro inks 10-year deal with Phoenix Group's ReAssure UK worth
The agreement, executed through Wipro and its 100% subsidiary,...
Centre announces that DPDP Rules nearing Finalisation by April
The government seeks to refine the rules for robust data protection, ensuri...
Home Ministry cracks down on PoS agents in digital arrest scam
Digital arrest scams are a growing cybercrime where victims are coerced or ...
ICONS OF INDIA : RAJESH NAMBIAR
Rajesh leads the company’s India associates and enhances relationshi...
Icons Of India : Dr. Arvind Gupta
Arvind Gupta is the Head and Co-Founder of the Digital India Foundatio...
Icons Of India : Daisy Chittilapilly
Daisy Chittilapilly is the President of Cisco’s India and SAARC regi...
LIC - Life Insurance Corporation of India
LIC is the largest state-owned life insurance company in India...
NPCI - National Payments Corporation of India
NPCI is an umbrella organization for operating retail payments and set...
ECIL - Electronics Corporation of India Limited
ECIL is distinguished by its diverse technological capabilities and it...
Indian Tech Talent Excelling The Tech World - Shantanu Narayen, CEO- Adobe Systems Incorporated
Shantanu Narayen, CEO of Adobe Systems Incorporated, is renowned for h...
Indian Tech Talent Excelling The Tech World - Rajiv Ramaswami, President & CEO, Nutanix Technologies
Rajiv Ramaswami, President and CEO of Nutanix, brings over 30 years of...
Indian Tech Talent Excelling The Tech World - Sundar Pichai, CEO- Alphabet Inc.
Sundar Pichai, the CEO of Google and its parent company Alphabet Inc.,...