VYPR
Unrated severityNVD Advisory· Published Nov 14, 2024· Updated Nov 14, 2024

PAN-OS: Authenticated XML External Entities (XXE) Injection Vulnerability

CVE-2024-5919

Description

A blind XML External Entities (XXE) injection vulnerability in the Palo Alto Networks PAN-OS software enables an authenticated attacker to exfiltrate arbitrary files from firewalls to an attacker controlled server. This attack requires network access to the firewall management interface.

Affected products

4

Patches

0

No patches discovered yet.

Vulnerability mechanics

AI mechanics synthesis has not run for this CVE yet.

References

1

News mentions

0

No linked articles in our index yet.