CVE Database
/

CVE-2024-5917

Back to search

CVE-2024-5917

Published: Nov 14, 2024

Modified: Jan 15, 2025

PUBLISHED

Description

A server-side request forgery in PAN-OS software enables an authenticated attacker with administrative privileges to use the administrative web interface as a proxy, which enables the attacker to view internal network resources not otherwise accessible.

VendorProductVersions

Palo Alto Networks

Cloud NGFW

unaffected
All

Palo Alto Networks

PAN-OS

unaffected
11.2.0
unaffected
11.1.0
unaffected
11.0.0
affected
10.2.0 - < 10.2.2
affected
10.1.0 - < 10.1.7

Weaknesses (CWE)

Security Training

Train your team to recognize and prevent security threats with our comprehensive security awareness program.

Start Training

Vulnerability Scanning

Discover vulnerabilities in your applications and infrastructure before attackers do.

Scan Now