Information Exposure Vulnerability in Palo Alto Networks PAN-OS software
CVE-2024-5916

6MEDIUM

Key Information:

Vendor
CVE Published:
14 August 2024

Badges

👾 Exploit Exists📰 News Worthy

What is CVE-2024-5916?

An information exposure vulnerability exists within Palo Alto Networks PAN-OS software, allowing local system administrators to unintentionally leak sensitive information such as secrets, passwords, and tokens associated with external systems. Specifically, a read-only administrator with access to the configuration log may be able to read this confidential data, potentially compromising system security and integrity.

Affected Version(s)

Cloud NGFW AWS Before 8/15

Cloud NGFW AWS Before 8/23

PAN-OS 10.2 < 10.2.8

News Articles

CERT-IN Warns About Vulnerabilities In Palo Alto Networks

CERT-IN has issued advisories regarding critical vulnerabilities in Palo Alto Networks applications. Users are urged to update to mitigate these risks.

References

CVSS V4

Score:
6
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
None
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
Unknown

Timeline

  • 👾

    Exploit known to exist

  • 📰

    First article discovered by The Cyber Express

  • Vulnerability published

.