CVE-2024-5920
Published: Nov 14, 2024
Modified: Apr 30, 2025
Description
A cross-site scripting (XSS) vulnerability in Palo Alto Networks PAN-OS software enables an authenticated read-write Panorama administrator to push a specially crafted configuration to a PAN-OS node. This enables impersonation of a legitimate PAN-OS administrator who can perform restricted actions on the PAN-OS node after the execution of JavaScript in the legitimate PAN-OS administrator's browser.
| Vendor | Product | Versions |
|---|---|---|
Palo Alto Networks | Cloud NGFW | unaffected All |
Palo Alto Networks | PAN-OS | unaffected 11.2.0affected 11.1.0 - < 11.1.4affected 11.0.0 - < 11.0.6affected 10.2.0 - < 10.2.7-h24affected 10.1.0 - < 10.1.14 |
Palo Alto Networks | Prisma Access | unaffected All |
Weaknesses (CWE)
References
Security Training
Train your team to recognize and prevent security threats with our comprehensive security awareness program.
Start TrainingVulnerability Scanning
Discover vulnerabilities in your applications and infrastructure before attackers do.
Scan Now