CVE-2024-5919: PAN-OS: Authenticated XML External Entities (XXE) Injection Vulnerability (Severity: LOW)
A blind XML External Entities (XXE) injection vulnerability in the Palo Alto Networks PAN-OS software enables an authenticated attacker to exfiltrate arbitrary files from firewalls to an attacker controlled server. This attack requires network access to the firewall management interface.
Affected Software
Remediation
Information
Event History
Frequently Asked Questions
What is the severity of CVE-2024-5919?
CVE-2024-5919 is classified as a critical severity vulnerability due to its potential for file exfiltration.
How do I fix CVE-2024-5919?
To mitigate CVE-2024-5919, update your PAN-OS to versions 10.2.6 or later, 10.1.11 or later, or 11.0.3 or later.
Who is affected by CVE-2024-5919?
CVE-2024-5919 affects Palo Alto Networks PAN-OS versions below 10.2.6, 10.1.11, and 11.0.3.
What impact does CVE-2024-5919 have?
The impact of CVE-2024-5919 allows an authenticated attacker to exfiltrate sensitive files from the firewall.
Can CVE-2024-5919 be exploited remotely?
CVE-2024-5919 requires network access to the firewall management interface, limiting its exploitation.