CVE-2024-5919
PAN-OS: Authenticated XML External Entities (XXE) Injection Vulnerability
Severity
Medium 5.1
CVSS 4.0
Exploited
Not listed
EPSS
0.003
27.2th percentile
Discovered by
Third party
Published by the vendor
Published
Nov 14, 2024
Assigned by palo_alto
Description
A blind XML External Entities (XXE) injection vulnerability in the Palo Alto Networks PAN-OS software enables an authenticated attacker to exfiltrate arbitrary files from firewalls to an attacker controlled server. This attack requires network access to the firewall management interface.
Weakness: CWE-611
Affected products
| Vendor | Product | Category | Matched by |
|---|---|---|---|
| Palo Alto Networks | Cloud NGFW | Firewall / NGFW | cna-assigner |
| Palo Alto Networks | PAN-OS | Firewall / NGFW | cna-assigner |
| Palo Alto Networks | Prisma Access | SASE / SSE / Secure Web | cna-assigner |
Vendor-reported affected versions (3)
- Palo Alto Networks · Cloud NGFW
- Palo Alto Networks · PAN-OS
- Palo Alto Networks · Prisma Access
Credit
Dan Marin of Deloitte
Vendor remediation
This issue is fixed in PAN-OS 10.1.10, PAN-OS 10.2.5, PAN-OS 11.0.2, and all later PAN-OS versions.