PT-2024-2309 · Palo Alto Networks · Palo Alto Networks Panorama

Omar Eissa

·

Published

2024-03-13

·

Updated

2026-01-30

·

CVE-2024-2433

CVSS v3.1

4.3

Medium

VectorAV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:L
Name of the Vulnerable Software and Affected Versions Palo Alto Networks Panorama (affected versions not specified)
Description The issue is related to improper authorization in the web interface of the management plane, allowing an authenticated read-only administrator to upload files and fill one of the disk partitions, preventing login to the web interface or download of PAN-OS, WildFire, and content images. This issue does not affect the dataplane.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Improper Privilege Management

Weakness Enumeration

Related Identifiers

BDU:2024-02243
CVE-2024-2433

Affected Products

Palo Alto Networks Panorama