Vulnerability Monitor

The vendors, products, and vulnerabilities you care about

CVE-2024-5917


A server-side request forgery in PAN-OS software enables an authenticated attacker with administrative privileges to use the administrative web interface as a proxy, which enables the attacker to view internal network resources not otherwise accessible.


Published

2024-11-14T10:15:08.607

Last Modified

2025-01-24T16:04:54.887

Status

Analyzed

Source

[email protected]

Severity

CVSSv3.1: 4.9 (MEDIUM)

Weaknesses
  • Type: Secondary
    CWE-918
  • Type: Primary
    CWE-918

Affected Vendors & Products
Type Vendor Product Version/Range Vulnerable?
Operating System paloaltonetworks pan-os < 10.1.7 Yes
Operating System paloaltonetworks pan-os < 10.2.2 Yes

References