Vulnerabilities > CVE-2024-5917 - Server-Side Request Forgery (SSRF) vulnerability in Paloaltonetworks Pan-Os

047910
CVSS 4.9 - MEDIUM
Attack vector
NETWORK
Attack complexity
LOW
Privileges required
HIGH
Confidentiality impact
HIGH
Integrity impact
NONE
Availability impact
NONE
network
low complexity
paloaltonetworks
CWE-918

Summary

A server-side request forgery in PAN-OS software enables an authenticated attacker with administrative privileges to use the administrative web interface as a proxy, which enables the attacker to view internal network resources not otherwise accessible.

Common Weakness Enumeration (CWE)