This issue affects only the web interface of the management plane; the dataplane is unaffected.
Metrics
Affected Vendors & Products
Solution
This issue is fixed in Panorama on PAN-OS 9.0.17-h4, PAN-OS 9.1.18, PAN-OS 10.1.12, PAN-OS 10.2.11, PAN-OS 11.0.4, and all later PAN-OS versions.
Workaround
This issue requires the attacker to have authenticated access to the PAN-OS web interface. You can mitigate the effect of this issue by following the Best Practices for Securing Administrative Access in the PAN-OS technical documentation at https://docs.paloaltonetworks.com/best-practices .
Link | Providers |
---|---|
https://security.paloaltonetworks.com/CVE-2024-2433 |
![]() ![]() ![]() |
No history.

Status: PUBLISHED
Assigner: palo_alto
Published:
Updated: 2024-08-12T18:54:08.465Z
Reserved: 2024-03-13T16:19:27.817Z
Link: CVE-2024-2433

Updated: 2024-08-01T19:11:53.562Z

Status : Awaiting Analysis
Published: 2024-03-13T18:15:08.893
Modified: 2024-11-21T09:09:44.803
Link: CVE-2024-2433

No data.

No data.