CVE-2024-5917

A server-side request forgery in PAN-OS software enables an authenticated attacker with administrative privileges to use the administrative web interface as a proxy, which enables the attacker to view internal network resources not otherwise accessible.
References
Configurations

Configuration 1 (hide)

OR cpe:2.3:o:paloaltonetworks:pan-os:*:*:*:*:*:*:*:*
cpe:2.3:o:paloaltonetworks:pan-os:*:*:*:*:*:*:*:*

History

No history.

Information

Published : 2024-11-14 10:15

Updated : 2025-01-24 16:04


NVD link : CVE-2024-5917

Mitre link : CVE-2024-5917

CVE.ORG link : CVE-2024-5917


JSON object : View

Products Affected

paloaltonetworks

  • pan-os
CWE
CWE-918

Server-Side Request Forgery (SSRF)