CVE-2024-5911

PAN-OS: File Upload Vulnerability in the Panorama Web Interface

Severity
High 7
CVSS 4.0
Exploited
Not listed
EPSS
0.006
46.3th percentile
Discovered by
Vendor
Vendor-published field
Published
Jul 10, 2024
Assigned by palo_alto

Description

An arbitrary file upload vulnerability in Palo Alto Networks Panorama software enables an authenticated read-write administrator with access to the web interface to disrupt system processes and crash the Panorama. Repeated attacks eventually cause the Panorama to enter maintenance mode, which requires manual intervention to bring the Panorama back online.

Weakness: CWE-434

Affected products

Vendor Product Category Matched by
Palo Alto Networks PAN-OS Firewall / NGFW cna-assigner
Palo Alto Networks Panorama Network & Security Management description
Vendor-reported products (3)
  • Palo Alto Networks · PAN-OS
  • Palo Alto Networks · Cloud NGFW — vendor states not affected
  • Palo Alto Networks · Prisma Access — vendor states not affected

Credit

Yasukazu Miyashita of Palo Alto Networks

Vendor remediation

This issue is fixed in PAN-OS 10.1.9, PAN-OS 10.2.4, and all later PAN-OS versions.

Something wrong here?