CVE-2024-5911
PAN-OS: File Upload Vulnerability in the Panorama Web Interface
Severity
High 7
CVSS 4.0
Exploited
Not listed
EPSS
0.006
44.2th percentile
Discovered by
Vendor
Published by the vendor
Published
Jul 10, 2024
Assigned by palo_alto
Description
An arbitrary file upload vulnerability in Palo Alto Networks Panorama software enables an authenticated read-write administrator with access to the web interface to disrupt system processes and crash the Panorama. Repeated attacks eventually cause the Panorama to enter maintenance mode, which requires manual intervention to bring the Panorama back online.
Weakness: CWE-434
Affected products
| Vendor | Product | Category | Matched by |
|---|---|---|---|
| Palo Alto Networks | Cloud NGFW | Firewall / NGFW | cna-assigner |
| Palo Alto Networks | PAN-OS | Firewall / NGFW | cna-assigner |
| Palo Alto Networks | Prisma Access | SASE / SSE / Secure Web | cna-assigner |
Vendor-reported affected versions (3)
- Palo Alto Networks · PAN-OS
- Palo Alto Networks · Cloud NGFW
- Palo Alto Networks · Prisma Access
Credit
Yasukazu Miyashita of Palo Alto Networks
Vendor remediation
This issue is fixed in PAN-OS 10.1.9, PAN-OS 10.2.4, and all later PAN-OS versions.