Back to search
CVE-2024-5917
Published: Nov 14, 2024
Modified: Jan 15, 2025
PUBLISHED
Description
A server-side request forgery in PAN-OS software enables an authenticated attacker with administrative privileges to use the administrative web interface as a proxy, which enables the attacker to view internal network resources not otherwise accessible.
| Vendor | Product | Versions |
|---|---|---|
Palo Alto Networks | Cloud NGFW | unaffected All |
Palo Alto Networks | PAN-OS | unaffected 11.2.0unaffected 11.1.0unaffected 11.0.0affected 10.2.0 - < 10.2.2affected 10.1.0 - < 10.1.7 |
Weaknesses (CWE)
References
https://security.paloaltonetworks.com/CVE-2024-5917
vendor-advisory
Security Training
Train your team to recognize and prevent security threats with our comprehensive security awareness program.
Start TrainingVulnerability Scanning
Discover vulnerabilities in your applications and infrastructure before attackers do.
Scan Now