PT-2024-5657 · Palo Alto Networks · Palo Alto Networks Panorama
Yasukazu Miyashita
·
Published
2024-06-12
·
Updated
2026-01-30
·
CVE-2024-5911
CVSS v4.0
7.0
High
| Vector | AV:N/AC:L/AT:N/PR:H/UI:N/VC:N/VI:L/VA:H/SC:N/SI:N/SA:N/AU:N/R:U/V:D/RE:M/U:Amber |
Name of the Vulnerable Software and Affected Versions
Palo Alto Networks Panorama (affected versions not specified)
Description
The issue is related to an arbitrary file upload vulnerability, allowing an authenticated read-write administrator with access to the web interface to disrupt system processes and crash the system. Repeated attacks can cause the system to enter maintenance mode, requiring manual intervention to bring it back online. This can be achieved by uploading a specially crafted file, potentially leading to a denial of service.
Recommendations
At the moment, there is no information about a newer version that contains a fix for this vulnerability.
Unrestricted File Upload
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Palo Alto Networks Panorama