CVE-2024-5911
PAN-OS: File Upload Vulnerability in the Panorama Web Interface
Severity
High 7
CVSS 4.0
Exploited
Not listed
EPSS
0.006
46.3th percentile
Discovered by
Vendor
Vendor-published field
Published
Jul 10, 2024
Assigned by palo_alto
Description
An arbitrary file upload vulnerability in Palo Alto Networks Panorama software enables an authenticated read-write administrator with access to the web interface to disrupt system processes and crash the Panorama. Repeated attacks eventually cause the Panorama to enter maintenance mode, which requires manual intervention to bring the Panorama back online.
Weakness: CWE-434
Affected products
| Vendor | Product | Category | Matched by |
|---|---|---|---|
| Palo Alto Networks | PAN-OS | Firewall / NGFW | cna-assigner |
| Palo Alto Networks | Panorama | Network & Security Management | description |
Vendor-reported products (3)
- Palo Alto Networks · PAN-OS
- Palo Alto Networks · Cloud NGFW — vendor states not affected
- Palo Alto Networks · Prisma Access — vendor states not affected
Credit
Yasukazu Miyashita of Palo Alto Networks
Vendor remediation
This issue is fixed in PAN-OS 10.1.9, PAN-OS 10.2.4, and all later PAN-OS versions.