CVE-2024-5917

PAN-OS: Server-Side Request Forgery in WildFire

Severity
Low 2.1
CVSS 4.0
Exploited
Not listed
EPSS
0.005
39.9th percentile
Discovered by
Third party
Vendor-published field
Published
Nov 14, 2024
Assigned by palo_alto

Description

A server-side request forgery in PAN-OS software enables an authenticated attacker with administrative privileges to use the administrative web interface as a proxy, which enables the attacker to view internal network resources not otherwise accessible.

Weakness: CWE-918

Affected products

Vendor Product Category Matched by
Palo Alto Networks Cloud NGFW Firewall / NGFW cna-assigner
Palo Alto Networks PAN-OS Firewall / NGFW cna-assigner
Vendor-reported products (7)
  • Palo Alto Networks · Cloud NGFW — vendor states not affected
  • Palo Alto Networks · PAN-OS
  • paloaltonetworks · cloud_ngfw
  • paloaltonetworks · pan-os
  • paloaltonetworks · pan-os
  • paloaltonetworks · pan-os
  • paloaltonetworks · pan-os

Credit

Michael Baker from AC3

Vendor remediation

This issue is fixed in PAN-OS 10.1.7, PAN-OS 10.2.2, and all later PAN-OS versions.

Something wrong here?