CVE-2024-5920: PAN-OS: Stored Cross-Site Scripting (XSS) Vulnerability in PAN-OS Enables Impersonation of a Legitimate Administrator (Severity: LOW)
A cross-site scripting (XSS) vulnerability in Palo Alto Networks PAN-OS software enables an authenticated read-write Panorama administrator to push a specially crafted configuration to a PAN-OS node. This enables impersonation of a legitimate PAN-OS administrator who can perform restricted actions on the PAN-OS node after the execution of JavaScript in the legitimate PAN-OS administrator's browser.
Affected Software
Remediation
Mitigation
Information
Event History
Frequently Asked Questions
What is the severity of CVE-2024-5920?
The severity of CVE-2024-5920 is classified as high due to its potential for unauthorized impersonation of a PAN-OS administrator.
How do I fix CVE-2024-5920?
To fix CVE-2024-5920, upgrade to PAN-OS versions 11.1.5, 11.0.7, 10.2.12, or 10.1.15 or later.
Which versions of PAN-OS are affected by CVE-2024-5920?
CVE-2024-5920 affects PAN-OS versions up to and including 11.1.4, 11.0.6, 10.2.11, and 10.1.14.
Can this vulnerability be exploited remotely in CVE-2024-5920?
CVE-2024-5920 requires authenticated access to the Panorama administrator account, hence it is not remotely exploitable.
What type of vulnerability is CVE-2024-5920?
CVE-2024-5920 is a cross-site scripting (XSS) vulnerability that impacts Palo Alto Networks PAN-OS software.