CVE-2024-5917
Severity CVSS v4.0:
LOW
Type:
CWE-918
Server-Side Request Forgery (SSRF)
Publication date:
14/11/2024
Last modified:
24/01/2025
Description
A server-side request forgery in PAN-OS software enables an authenticated attacker with administrative privileges to use the administrative web interface as a proxy, which enables the attacker to view internal network resources not otherwise accessible.
Impact
Base Score 4.0
2.10
Severity 4.0
LOW
Base Score 3.x
4.90
Severity 3.x
MEDIUM
Vulnerable products and versions
| CPE | From | Up to |
|---|---|---|
| cpe:2.3:o:paloaltonetworks:pan-os:*:*:*:*:*:*:*:* | 10.1.0 (including) | 10.1.7 (excluding) |
| cpe:2.3:o:paloaltonetworks:pan-os:*:*:*:*:*:*:*:* | 10.2.0 (including) | 10.2.2 (excluding) |
To consult the complete list of CPE names with products and versions, see this page



