CVE-2024-5920

CVSS V2 None CVSS V3 None
Description
A cross-site scripting (XSS) vulnerability in Palo Alto Networks PAN-OS software enables an authenticated read-write Panorama administrator to push a specially crafted configuration to a PAN-OS node. This enables impersonation of a legitimate PAN-OS administrator who can perform restricted actions on the PAN-OS node after the execution of JavaScript in the legitimate PAN-OS administrator's browser.
Overview
  • CVE ID
  • CVE-2024-5920
  • Assigner
  • palo_alto
  • Vulnerability Status
  • PUBLISHED
  • Published Version
  • 2024-11-14T09:40:14.513Z
  • Last Modified Date
  • 2024-11-14T19:35:21.731Z
References
Reference URL Reference Tags
https://security.paloaltonetworks.com/CVE-2024-5920 vendor-advisory
History
Created Old Value New Value Data Type Notes
2024-11-15 13:20:36 Added to TrackCVE