Home
MEDIUM: 6.1 CVSS:3.1/AV:P/AC:H/PR:H/UI:N/S:U/C:H/I:H/A:HDefault status
unaffected
10.1.0 (custom) before 10.1.14-h2
affected
10.2.0 (custom) before 10.2.10
affected
11.0.0 (custom) before 11.0.5
affected
11.1.0 (custom) before 11.1.4
affected
11.2.0 (custom) before 11.2.1
affected
Default status
unaffected
None
affected
All
unaffected
Default status
unaffected
None
affected
All
unaffected
Description
An improper input validation vulnerability in Palo Alto Networks PAN-OS software enables an attacker with the ability to tamper with the physical file system to elevate privileges.
Problem types
CWE-20 Improper Input Validation
Product status
10.1.0 (custom) before 10.1.14-h2
10.2.0 (custom) before 10.2.10
11.0.0 (custom) before 11.0.5
11.1.0 (custom) before 11.1.4
11.2.0 (custom) before 11.2.1
None
All
None
All
Timeline
| 2024-07-10: | Initial publication |
Credits
Independent Security Researcher Pear1y
Joel Land of CISA Vulnerability Response and Coordination
rqu
Enrique Castillo of Palo Alto Networks
References
security.paloaltonetworks.com/CVE-2024-5913
security.paloaltonetworks.com/CVE-2024-5913