CVE-2024-5911

PAN-OS: File Upload Vulnerability in the Panorama Web Interface

Severity
High 7
CVSS 4.0
Exploited
Not listed
EPSS
0.006
44.2th percentile
Discovered by
Vendor
Published by the vendor
Published
Jul 10, 2024
Assigned by palo_alto

Description

An arbitrary file upload vulnerability in Palo Alto Networks Panorama software enables an authenticated read-write administrator with access to the web interface to disrupt system processes and crash the Panorama. Repeated attacks eventually cause the Panorama to enter maintenance mode, which requires manual intervention to bring the Panorama back online.

Weakness: CWE-434

Affected products

Vendor Product Category Matched by
Palo Alto Networks Cloud NGFW Firewall / NGFW cna-assigner
Palo Alto Networks PAN-OS Firewall / NGFW cna-assigner
Palo Alto Networks Prisma Access SASE / SSE / Secure Web cna-assigner
Vendor-reported affected versions (3)
  • Palo Alto Networks · PAN-OS
  • Palo Alto Networks · Cloud NGFW
  • Palo Alto Networks · Prisma Access

Credit

Yasukazu Miyashita of Palo Alto Networks

Vendor remediation

This issue is fixed in PAN-OS 10.1.9, PAN-OS 10.2.4, and all later PAN-OS versions.