CVE-2024-5919
14.11.2024, 10:15
A blind XML External Entities (XXE) injection vulnerability in the Palo Alto Networks PAN-OS software enables an authenticated attacker to exfiltrate arbitrary files from firewalls to an attacker controlled server. This attack requires network access to the firewall management interface.Enginsight
Vendor | Product | Version |
---|---|---|
paloaltonetworks | pan-os | 10.1.0 ≤ 𝑥 < 10.1.10 |
paloaltonetworks | pan-os | 10.2.0 ≤ 𝑥 < 10.2.5 |
paloaltonetworks | pan-os | 11.0.0 ≤ 𝑥 < 11.0.2 |
𝑥
= Vulnerable software versions