CVE-2024-5917

Severity CVSS v4.0:
LOW
Type:
CWE-918 Server-Side Request Forgery (SSRF)
Publication date:
14/11/2024
Last modified:
24/01/2025

Description

A server-side request forgery in PAN-OS software enables an authenticated attacker with administrative privileges to use the administrative web interface as a proxy, which enables the attacker to view internal network resources not otherwise accessible.

Vulnerable products and versions

CPE From Up to
cpe:2.3:o:paloaltonetworks:pan-os:*:*:*:*:*:*:*:* 10.1.0 (including) 10.1.7 (excluding)
cpe:2.3:o:paloaltonetworks:pan-os:*:*:*:*:*:*:*:* 10.2.0 (including) 10.2.2 (excluding)


References to Advisories, Solutions, and Tools