CVE-2024-2433: Palo Alto Networks PAN-OS

Low severity, CVSS 2.7. EPSS: 0.6% chance of exploitation in the next 30 days.

An improper authorization vulnerability in Palo Alto Networks Panorama software enables an authenticated read-only administrator to upload files using the web interface and completely fill one of the disk partitions with those uploaded files, which prevents the ability to log into the web interface or to download PAN-OS, WildFire, and content images. This issue affects only the web interface of the management plane; the dataplane is unaffected.

Affected products

  • Palo Alto Networks PAN-OS: before 9.0.17 (fixed in 9.0.17); from 9.1.0, before 9.1.17 (fixed in 9.1.17); from 10.1.0, before 10.1.12 (fixed in 10.1.12); from 10.2.0, before 10.2.8 (fixed in 10.2.8); from 11.0.0, before 11.0.3 (fixed in 11.0.3); version 9.0.17 only

Published 2024-03-13. Last modified 2026-06-17.