CVE-2024-5911

PAN-OS: File Upload Vulnerability in the Panorama Web Interface

Severity
High 7
CVSS 4.0
Remote, needs privileges or user interaction what this means
Exploited
Not listed
EPSS
0.006
45.6th percentile
Discovered by
Vendor
Vendor-published field
Published
Jul 10, 2024
Assigned by palo_alto

Description

An arbitrary file upload vulnerability in Palo Alto Networks Panorama software enables an authenticated read-write administrator with access to the web interface to disrupt system processes and crash the Panorama. Repeated attacks eventually cause the Panorama to enter maintenance mode, which requires manual intervention to bring the Panorama back online.

Weakness: CWE-434

Affected products

Vendor Product Category Matched by
Palo Alto Networks PAN-OS Check your version Firewall / NGFW cna-assigner
Palo Alto Networks Panorama Network & Security Management description
Vendor-reported products (3)
  • Palo Alto Networks · PAN-OS
  • Palo Alto Networks · Cloud NGFW — vendor states not affected
  • Palo Alto Networks · Prisma Access — vendor states not affected

Credit

Yasukazu Miyashita of Palo Alto Networks

Vendor remediation

This issue is fixed in PAN-OS 10.1.9, PAN-OS 10.2.4, and all later PAN-OS versions.

Something wrong here?