PT-2024-8352 · Palo Alto Networks · Pan-Os

Bobby Storey

·

Published

2024-11-13

·

Updated

2025-01-24

·

CVE-2024-2552

CVSS v4.0

6.8

Medium

VectorAV:L/AC:L/AT:N/PR:H/UI:N/VC:N/VI:H/VA:H/SC:N/SI:N/SA:N/AU:N/R:U/V:C/RE:M/U:Amber
Name of the Vulnerable Software and Affected Versions Palo Alto Networks PAN-OS (affected versions not specified)
Description A command injection issue in the software enables an authenticated administrator to bypass system restrictions in the management plane and delete files on the firewall. The vulnerability is also related to incorrect restriction of a directory path name with limited access, which can allow an attacker to elevate their privileges.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Path traversal

Weakness Enumeration

Related Identifiers

BDU:2024-09908
CVE-2024-2552

Affected Products

Pan-Os