CVE-2024-5919
Severity CVSS v4.0:
MEDIUM
Type:
CWE-611
Improper Restriction of XML External Entity Reference ('XXE')
Publication date:
14/11/2024
Last modified:
24/01/2025
Description
A blind XML External Entities (XXE) injection vulnerability in the Palo Alto Networks PAN-OS software enables an authenticated attacker to exfiltrate arbitrary files from firewalls to an attacker controlled server. This attack requires network access to the firewall management interface.
Impact
Base Score 4.0
5.10
Severity 4.0
MEDIUM
Base Score 3.x
6.50
Severity 3.x
MEDIUM
Vulnerable products and versions
| CPE | From | Up to |
|---|---|---|
| cpe:2.3:o:paloaltonetworks:pan-os:*:*:*:*:*:*:*:* | 10.1.0 (including) | 10.1.10 (excluding) |
| cpe:2.3:o:paloaltonetworks:pan-os:*:*:*:*:*:*:*:* | 10.2.0 (including) | 10.2.5 (excluding) |
| cpe:2.3:o:paloaltonetworks:pan-os:*:*:*:*:*:*:*:* | 11.0.0 (including) | 11.0.2 (excluding) |
To consult the complete list of CPE names with products and versions, see this page



