4.3

CVE-2024-2433

An improper authorization vulnerability in Palo Alto Networks Panorama software enables an authenticated read-only administrator to upload files using the web interface and completely fill one of the disk partitions with those uploaded files, which prevents the ability to log into the web interface or to download PAN-OS, WildFire, and content images. 



This issue affects only the web interface of the management plane; the dataplane is unaffected.

Verknüpft mit AI von unstrukturierten Daten zu bestehenden CPE der NVD
This information is available to logged-in users.
Daten sind bereitgestellt durch das CVE Programm von Authorized Data Publishers (ADP) (Unstrukturiert)
Vendorpaloaltonetworks
Product pan-os
Default Statusunaffected
Version < 9.0.17-h4
Version 9.0
Status affected
Version < 9.1.17
Version 9.1
Status affected
Version < 10.1.12
Version 10.1
Status affected
Version < 10.2.8
Version 10.2
Status affected
Version < 11.0.3
Version 11.0
Status affected
Vendorpaloaltonetworks
Product pan-os
Default Statusunaffected
Version 11.1.0
Status unaffected
Vendorpaloaltonetworks
Product cloud_ngfw
Default Statusunaffected
Version <= *
Version 0
Status affected
Vendorpaloaltonetworks
Product prisma_access
Default Statusunaffected
Version <= *
Version 0
Status affected
Zu dieser CVE wurde keine CISA KEV oder CERT.AT-Warnung gefunden.
EPSS Metriken
Type Source Score Percentile
EPSS FIRST.org 0.04% 0.094
CVSS Metriken
Source Base Score Exploit Score Impact Score Vector string
psirt@paloaltonetworks.com 4.3 2.8 1.4
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:L
CWE-269 Improper Privilege Management

The product does not properly assign, modify, track, or check privileges for an actor, creating an unintended sphere of control for that actor.