CVE-2024-5917: Palo Alto Networks PAN-OS
Medium severity, CVSS 4.9. EPSS: 0.5% chance of exploitation in the next 30 days.
A server-side request forgery in PAN-OS software enables an authenticated attacker with administrative privileges to use the administrative web interface as a proxy, which enables the attacker to view internal network resources not otherwise accessible.
Affected products
- Palo Alto Networks PAN-OS: from 10.1.0, before 10.1.7 (fixed in 10.1.7); from 10.2.0, before 10.2.2 (fixed in 10.2.2)
Published 2024-11-14. Last modified 2026-06-17.