CVE-2024-5917: PAN-OS: Server-Side Request Forgery in WildFire (Severity: LOW)
A server-side request forgery in PAN-OS software enables an authenticated attacker to use the administrative web interface as a proxy, which enables the attacker to view internal network resources not otherwise accessible.
Other sources
A server-side request forgery in PAN-OS software enables an authenticated attacker with administrative privileges to use the administrative web interface as a proxy, which enables the attacker to view internal network resources not otherwise accessible.
— MITRE
Affected Software
Remediation
Information
Mitigation
Information
Event History
Frequently Asked Questions
What is the severity of CVE-2024-5917?
CVE-2024-5917 is classified as a critical vulnerability due to its potential impact on internal network security.
How do I fix CVE-2024-5917?
To fix CVE-2024-5917, upgrade the affected PAN-OS versions to at least 10.2.2 or 10.1.7.
What software is affected by CVE-2024-5917?
CVE-2024-5917 affects Palo Alto Networks Cloud NGFW and specific versions of PAN-OS including 10.2.0, 10.2.2, and 10.1.0 to 10.1.7.
What type of vulnerability is CVE-2024-5917?
CVE-2024-5917 is a server-side request forgery (SSRF) vulnerability.
Can CVE-2024-5917 be exploited remotely?
CVE-2024-5917 requires authentication, meaning an attacker must have access to the administrative web interface to exploit the vulnerability.