CVE-2024-5919

MEDIUMCVSS 6.5/10EPSS 0.35%

Last modified

CVE-2024-5919 is a medium-severity vulnerability rated 6.5/10 on the CVSS scale. A blind XML External Entities (XXE) injection vulnerability in the Palo Alto Networks PAN-OS software enables an authenticated attacker to exfiltrate arbitrary files from firewalls to an attacker controlled server. This attack requires network access to the firewall management interface.. EPSS estimates a 0.35% chance of exploitation in the next 30 days.

Description

A blind XML External Entities (XXE) injection vulnerability in the Palo Alto Networks PAN-OS software enables an authenticated attacker to exfiltrate arbitrary files from firewalls to an attacker controlled server. This attack requires network access to the firewall management interface.

Metrics

Weakness Enumeration

Affected Software

VendorProductVersions
PaloaltonetworksPan-Os>= 10.1.0, < 10.1.10
PaloaltonetworksPan-Os>= 10.2.0, < 10.2.5
PaloaltonetworksPan-Os>= 11.0.0, < 11.0.2

References

Timeline

Published
Last Modified
Status
Analyzed

Frequently Asked Questions

What is CVE-2024-5919?
A blind XML External Entities (XXE) injection vulnerability in the Palo Alto Networks PAN-OS software enables an authenticated attacker to exfiltrate arbitrary files from firewalls to an attacker controlled server. This attack requires network access to the firewall management interface.
How severe is CVE-2024-5919?
CVE-2024-5919 has a CVSS score of 6.5/10 (MEDIUM severity). The EPSS model estimates a 0.35% probability of exploitation in the next 30 days.
How do I fix CVE-2024-5919?
Check the vendor references and advisories linked above for patched versions and mitigation guidance. You can also run a Strix scan to test if your systems are affected.

How Strix Helps

Related CVEs from 2024

Are you affected by CVE-2024-5919?

Run a free Strix scan to check your systems for this vulnerability.

Scan your code now

Source: NVD / NIST