CVE-2024-5920

A cross-site scripting (XSS) vulnerability in Palo Alto Networks PAN-OS software enables an authenticated read-write Panorama administrator to push a specially crafted configuration to a PAN-OS node. This enables impersonation of a legitimate PAN-OS administrator who can perform restricted actions on the PAN-OS node after the execution of JavaScript in the legitimate PAN-OS administrator's browser.
References
Configurations

Configuration 1 (hide)

OR cpe:2.3:o:paloaltonetworks:pan-os:*:*:*:*:*:*:*:*
cpe:2.3:o:paloaltonetworks:pan-os:*:*:*:*:*:*:*:*
cpe:2.3:o:paloaltonetworks:pan-os:*:*:*:*:*:*:*:*
cpe:2.3:o:paloaltonetworks:pan-os:*:*:*:*:*:*:*:*

History

24 Jan 2025, 16:06

Type Values Removed Values Added
CPE cpe:2.3:o:paloaltonetworks:pan-os:*:*:*:*:*:*:*:*
References () https://security.paloaltonetworks.com/CVE-2024-5920 - () https://security.paloaltonetworks.com/CVE-2024-5920 - Vendor Advisory
First Time Paloaltonetworks pan-os
Paloaltonetworks
CVSS v2 : unknown
v3 : unknown
v2 : unknown
v3 : 4.8

15 Nov 2024, 13:58

Type Values Removed Values Added
Summary
  • (es) Una vulnerabilidad de cross-site scripting (XSS) en el software PAN-OS de Palo Alto Networks permite que un administrador de Panorama autenticado de lectura y escritura envíe una configuración especialmente manipulada a un nodo PAN-OS. Esto permite la suplantación de un administrador legítimo de PAN-OS que puede realizar acciones restringidas en el nodo PAN-OS después de la ejecución de JavaScript en el navegador del administrador legítimo de PAN-OS.

14 Nov 2024, 10:15

Type Values Removed Values Added
New CVE

Information

Published : 2024-11-14 10:15

Updated : 2025-01-24 16:06


NVD link : CVE-2024-5920

Mitre link : CVE-2024-5920

CVE.ORG link : CVE-2024-5920


JSON object : View

Products Affected

paloaltonetworks

  • pan-os
CWE
CWE-79

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')