PT-2024-5657 · Palo Alto Networks · Palo Alto Networks Panorama

Yasukazu Miyashita

·

Published

2024-06-12

·

Updated

2026-01-30

·

CVE-2024-5911

CVSS v4.0

7.0

High

VectorAV:N/AC:L/AT:N/PR:H/UI:N/VC:N/VI:L/VA:H/SC:N/SI:N/SA:N/AU:N/R:U/V:D/RE:M/U:Amber
Name of the Vulnerable Software and Affected Versions Palo Alto Networks Panorama (affected versions not specified)
Description The issue is related to an arbitrary file upload vulnerability, allowing an authenticated read-write administrator with access to the web interface to disrupt system processes and crash the system. Repeated attacks can cause the system to enter maintenance mode, requiring manual intervention to bring it back online. This can be achieved by uploading a specially crafted file, potentially leading to a denial of service.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Unrestricted File Upload

Weakness Enumeration

Related Identifiers

BDU:2024-06370
CVE-2024-5911

Affected Products

Palo Alto Networks Panorama