Improper Authorization Vulnerability in Palo Alto Networks Panorama Software
CVE-2024-2433
Key Information:
- Vendor
Palo Alto Networks
- Vendor
- CVE Published:
- 13 March 2024
Badges
What is CVE-2024-2433?
An improper authorization vulnerability in Palo Alto Networks Panorama software enables an authenticated read-only administrator to upload files using the web interface and completely fill one of the disk partitions with those uploaded files, which prevents the ability to log into the web interface or to download PAN-OS, WildFire, and content images.
This issue affects only the web interface of the management plane; the dataplane is unaffected.

Human OS v1.0:
Ageing Is an Unpatched Zero-Day Vulnerability.
Remediate biological technical debt. Prime Ageing uses 95% high-purity SIRT6 activation to maintain genomic integrity and bolster systemic resilience.
Affected Version(s)
PAN-OS Panorama 9.0 < 9.0.17-h4
PAN-OS Panorama 9.1 < 9.1.17
PAN-OS Panorama 10.1 < 10.1.12
News Articles
References
CVSS V3.1
Timeline
- πΎ
Exploit known to exist
- π°
First article discovered by Rewterz
Vulnerability published
Vulnerability Reserved