Tracker / CVE-2024-2433
CVE-2024-2433
Medium 4.3
An improper authorization vulnerability in Palo Alto Networks Panorama software enables an authenticated read-only administrator to upload files using the web interface and completely fill one of the disk partitions with those uploaded files, which prevents the ability to log into the web interface or to download PAN-OS, WildFire, and content images. This issue affects only the web interface of the management plane; the dataplane is unaffected.
Affected products and versions
| paloaltonetworks | pan-os |
|---|---|
| paloaltonetworks | pan-os · … → 9.0.17 |
| paloaltonetworks | pan-os · 10.1.0 → 10.1.12 |
| paloaltonetworks | pan-os · 10.2.0 → 10.2.8 |
| paloaltonetworks | pan-os · 11.0.0 → 11.0.3 |
| paloaltonetworks | pan-os · 9.1.0 → 9.1.17 |
Analysis
This page is not indexable yet.Until it carries original analysis — what it actually exposes, how to check in two minutes whether a system was touched, what to do if it was — the page stays noindex. The database decides that, not the template.