CVE-2024-5911: PAN-OS: File Upload Vulnerability in the Panorama Web Interface
An arbitrary file upload vulnerability in Palo Alto Networks Panorama software enables an authenticated read-write administrator with access to the web interface to disrupt system processes and crash the Panorama. Repeated attacks eventually cause the Panorama to enter maintenance mode, which requires manual intervention to bring the Panorama back online.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
Palo Alto Networks PAN-OS (Panorama)to a version that resolves this vulnerability.Fixed in 10.1.9 - Upgrade
Upgrade
Palo Alto Networks PAN-OS (Panorama)to a version that resolves this vulnerability.Fixed in 10.2.4 - Operational
If repeated attacks put Panorama into maintenance mode, perform the required manual intervention to bring Panorama back online.
Event History
Frequently Asked Questions
What is the severity of CVE-2024-5911?
CVE-2024-5911 is classified as a critical vulnerability due to its ability to allow arbitrary file uploads and disrupt system processes.
How do I fix CVE-2024-5911?
To fix CVE-2024-5911, ensure that you apply the latest security patches provided by Palo Alto Networks for Panorama software.
Who is affected by CVE-2024-5911?
CVE-2024-5911 affects authenticated read-write administrators of Palo Alto Networks Panorama software.
What are the potential impacts of CVE-2024-5911?
The potential impacts of CVE-2024-5911 include system crashes and prolonged maintenance mode for the Panorama system.
Is CVE-2024-5911 being actively exploited?
At this time, there are no confirmed reports of active exploitation of CVE-2024-5911, but it is recommended to mitigate the risk immediately.