Back to search
CVE-2024-5919
Published: Nov 14, 2024
Modified: Nov 14, 2024
PUBLISHED
Description
A blind XML External Entities (XXE) injection vulnerability in the Palo Alto Networks PAN-OS software enables an authenticated attacker to exfiltrate arbitrary files from firewalls to an attacker controlled server. This attack requires network access to the firewall management interface.
| Vendor | Product | Versions |
|---|---|---|
Palo Alto Networks | Cloud NGFW | unaffected All |
Palo Alto Networks | PAN-OS | unaffected 11.2.0unaffected 11.1.0affected 11.0.0 - < 11.0.2affected 10.2.0 - < 10.2.5affected 10.1.0 - < 10.1.10 |
Palo Alto Networks | Prisma Access | unaffected All |
Weaknesses (CWE)
References
https://security.paloaltonetworks.com/CVE-2024-5919
vendor-advisory
Security Training
Train your team to recognize and prevent security threats with our comprehensive security awareness program.
Start TrainingVulnerability Scanning
Discover vulnerabilities in your applications and infrastructure before attackers do.
Scan Now