CVE-2024-5920 — Cross-site Scripting in Palo Alto Networks Pan-os
Severity
4.6MEDIUMNVD
EPSS
0.6%
top 30.95%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedNov 14
Description
A cross-site scripting (XSS) vulnerability in Palo Alto Networks PAN-OS software enables an authenticated read-write Panorama administrator to push a specially crafted configuration to a PAN-OS node. This enables impersonation of a legitimate PAN-OS administrator who can perform restricted actions on the PAN-OS node after the execution of JavaScript in the legitimate PAN-OS administrator's browser.
CVSS vector
CVSS:4.0/AV:N/AC:L/AT:N/PR:H/UI:A/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N
Affected Packages5 packages
🔴Vulnerability Details
2GHSA▶
GHSA-xx8r-3wgj-j632: A cross-site scripting (XSS) vulnerability in Palo Alto Networks PAN-OS software enables an authenticated read-write Panorama administrator to push a↗2024-11-14
CVEList▶
PAN-OS: Stored Cross-Site Scripting (XSS) Vulnerability in PAN-OS Enables Impersonation of a Legitimate Administrator↗2024-11-14
📋Vendor Advisories
1Palo Alto▶
PAN-OS: Stored Cross-Site Scripting (XSS) Vulnerability in PAN-OS Enables Impersonation of a Legitimate Administrator↗