CVE-2024-2552

A command injection vulnerability in Palo Alto Networks PAN-OS software enables an authenticated administrator to bypass system restrictions in the management plane and delete files on the firewall.
Path Traversal
ProviderTypeBase ScoreAtk. VectorAtk. ComplexityPriv. RequiredVector
NISTNIST
6 MEDIUM
LOCAL
LOW
HIGH
CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:N/I:H/A:H
palo_altoCNA
---
---
CISA-ADPADP
---
---
Base Score
CVSS 3.x
EPSS Score
Percentile: 36%
VendorProductVersion
paloaltonetworkspan-os
10.2.0 ≤
𝑥
< 10.2.7
paloaltonetworkspan-os
11.0.0 ≤
𝑥
< 11.0.6
paloaltonetworkspan-os
11.1.0 ≤
𝑥
< 11.1.4
paloaltonetworkspan-os
11.2.0 ≤
𝑥
< 11.2.4
paloaltonetworkspan-os
10.2.7
paloaltonetworkspan-os
10.2.7:h1
paloaltonetworkspan-os
10.2.7:h12
paloaltonetworkspan-os
10.2.7:h16
paloaltonetworkspan-os
10.2.7:h18
paloaltonetworkspan-os
10.2.7:h19
paloaltonetworkspan-os
10.2.7:h3
paloaltonetworkspan-os
10.2.7:h6
paloaltonetworkspan-os
10.2.7:h8
paloaltonetworkspan-os
10.2.8
paloaltonetworkspan-os
10.2.8:h10
paloaltonetworkspan-os
10.2.8:h13
paloaltonetworkspan-os
10.2.8:h15
paloaltonetworkspan-os
10.2.8:h3
paloaltonetworkspan-os
10.2.8:h4
paloaltonetworkspan-os
10.2.9
paloaltonetworkspan-os
10.2.9:h1
paloaltonetworkspan-os
10.2.9:h11
paloaltonetworkspan-os
10.2.9:h14
paloaltonetworkspan-os
10.2.9:h16
paloaltonetworkspan-os
10.2.9:h9
paloaltonetworkspan-os
10.2.10
paloaltonetworkspan-os
10.2.10:h2
paloaltonetworkspan-os
10.2.10:h3
paloaltonetworkspan-os
10.2.10:h4
paloaltonetworkspan-os
10.2.10:h5
paloaltonetworkspan-os
10.2.10:h7
paloaltonetworkspan-os
10.2.10:h9
paloaltonetworkspan-os
10.2.11
paloaltonetworkspan-os
10.2.11:h1
paloaltonetworkspan-os
10.2.11:h2
paloaltonetworkspan-os
10.2.11:h3
paloaltonetworkspan-os
10.2.11:h4
paloaltonetworkspan-os
10.2.11:h6
paloaltonetworkspan-os
11.1.4
paloaltonetworkspan-os
11.1.4:h1
paloaltonetworkspan-os
11.1.4:h4
paloaltonetworkspan-os
11.1.4:h7
𝑥
= Vulnerable software versions