CVE-2024-2433
Status: AnalyzedLow (2.7)—
An improper authorization vulnerability in Palo Alto Networks Panorama software enables an authenticated read-only administrator to upload files using the web interface and completely fill one of the disk partitions with those uploaded files, which prevents the ability to log into the web interface or to download PAN-OS, WildFire, and content images.
This issue affects only the web interface of the management plane; the dataplane is unaffected.
CVSS
- Version: 3.1
- Vector: CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:N/I:N/A:L
- Base score: 2.7
Exploitation probability (EPSS)
- Probability of exploitation in the next 30 days: 0.57%
- Percentile among all scored CVEs: 45
- Score date: 10/7/2026
EPSS (Exploit Prediction Scoring System, FIRST) estimates how likely a vulnerability is to be exploited in the wild within 30 days. It complements CVSS (impact) and CISA KEV (confirmed exploitation).
Affected technologies (1)
CWEs
- CWE-269
References
Raw JSON (NVD)
Show
{
"id": "CVE-2024-2433",
"cveTags": [],
"metrics": {
"ssvcV203": [
{
"source": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
"ssvcData": {
"id": "CVE-2024-2433",
"role": "CISA Coordinator",
"options": [
{
"exploitation": "none"
},
{
"automatable": "no"
},
{
"technicalImpact": "partial"
}
],
"version": "2.0.3",
"timestamp": "2026-05-13T20:17:01.821924Z"
}
}
],
"cvssMetricV31": [
{
"type": "Secondary",
"source": "psirt@paloaltonetworks.com",
"cvssData": {
"scope": "UNCHANGED",
"version": "3.1",
"baseScore": 4.3,
"attackVector": "NETWORK",
"baseSeverity": "MEDIUM",
"vectorString": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:L",
"integrityImpact": "NONE",
"userInteraction": "NONE",
"attackComplexity": "LOW",
"availabilityImpact": "LOW",
"privilegesRequired": "LOW",
"confidentialityImpact": "NONE"
},
"impactScore": 1.4,
"exploitabilityScore": 2.8
},
{
"type": "Primary",
"source": "nvd@nist.gov",
"cvssData": {
"scope": "UNCHANGED",
"version": "3.1",
"baseScore": 2.7,
"attackVector": "NETWORK",
"baseSeverity": "LOW",
"vectorString": "CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:N/I:N/A:L",
"integrityImpact": "NONE",
"userInteraction": "NONE",
"attackComplexity": "LOW",
"availabilityImpact": "LOW",
"privilegesRequired": "HIGH",
"confidentialityImpact": "NONE"
},
"impactScore": 1.4,
"exploitabilityScore": 1.2
}
]
},
"affected": [
{
"source": "psirt@paloaltonetworks.com",
"affectedData": [
{
"vendor": "Palo Alto Networks",
"product": "PAN-OS",
"versions": [
{
"status": "affected",
"changes": [
{
"at": "9.0.17-h4",
"status": "unaffected"
}
],
"version": "9.0",
"lessThan": "9.0.17-h4",
"versionType": "custom"
},
{
"status": "affected",
"changes": [
{
"at": "9.1.17",
"status": "unaffected"
}
],
"version": "9.1",
"lessThan": "9.1.17",
"versionType": "custom"
},
{
"status": "affected",
"changes": [
{
"at": "10.1.12",
"status": "unaffected"
}
],
"version": "10.1",
"lessThan": "10.1.12",
"versionType": "custom"
},
{
"status": "affected",
"changes": [
{
"at": "10.2.8",
"status": "unaffected"
}
],
"version": "10.2",
"lessThan": "10.2.8",
"versionType": "custom"
},
{
"status": "affected",
"changes": [
{
"at": "11.0.3",
"status": "unaffected"
}
],
"version": "11.0",
"lessThan": "11.0.3",
"versionType": "custom"
},
{
"status": "unaffected",
"version": "11.1"
}
],
"platforms": [
"Panorama"
],
"defaultStatus": "unaffected"
},
{
"vendor": "Palo Alto Networks",
"product": "Cloud NGFW",
"versions": [
{
"status": "unaffected",
"version": "All"
}
],
"defaultStatus": "unaffected"
},
{
"vendor": "Palo Alto Networks",
"product": "Prisma Access",
"versions": [
{
"status": "unaffected",
"version": "All"
}
],
"defaultStatus": "unaffected"
}
]
}
],
"published": "2024-03-13T18:15:08.893",
"references": [
{
"url": "https://security.paloaltonetworks.com/CVE-2024-2433",
"tags": [
"Vendor Advisory"
],
"source": "psirt@paloaltonetworks.com"
},
{
"url": "https://security.paloaltonetworks.com/CVE-2024-2433",
"tags": [
"Vendor Advisory"
],
"source": "af854a3a-2127-422b-91ae-364da2661108"
}
],
"vulnStatus": "Analyzed",
"weaknesses": [
{
"type": "Secondary",
"source": "psirt@paloaltonetworks.com",
"description": [
{
"lang": "en",
"value": "CWE-269"
}
]
}
],
"descriptions": [
{
"lang": "en",
"value": "An improper authorization vulnerability in Palo Alto Networks Panorama software enables an authenticated read-only administrator to upload files using the web interface and completely fill one of the disk partitions with those uploaded files, which prevents the ability to log into the web interface or to download PAN-OS, WildFire, and content images. \n\n\n\nThis issue affects only the web interface of the management plane; the dataplane is unaffected.\n"
},
{
"lang": "es",
"value": "Una vulnerabilidad de autorización inadecuada en el software Panorama de Palo Alto Networks permite que un administrador autenticado de solo lectura cargue archivos utilizando la interfaz web y llene completamente una de las particiones del disco con esos archivos cargados, lo que impide iniciar sesión en la interfaz web o descargarlos. PAN-OS, WildFire e imágenes de contenido. Este problema afecta únicamente a la interfaz web del plano de gestión; el plano de datos no se ve afectado."
}
],
"lastModified": "2026-06-17T07:24:31.737",
"configurations": [
{
"nodes": [
{
"negate": false,
"cpeMatch": [
{
"criteria": "cpe:2.3:o:paloaltonetworks:pan-os:*:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "DB6AEA1F-5E27-41F9-A6E4-12BCD88F5688",
"versionEndExcluding": "9.0.17"
},
{
"criteria": "cpe:2.3:o:paloaltonetworks:pan-os:*:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "9F9FFBA6-7008-422B-9CF1-E37CA62081EB",
"versionEndExcluding": "9.1.17",
"versionStartIncluding": "9.1.0"
},
{
"criteria": "cpe:2.3:o:paloaltonetworks:pan-os:*:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "AC18B586-8FE2-4362-9F60-490FCB52569F",
"versionEndExcluding": "10.1.12",
"versionStartIncluding": "10.1.0"
},
{
"criteria": "cpe:2.3:o:paloaltonetworks:pan-os:*:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "C430BDF9-C688-47F9-BE38-D75460AE5B17",
"versionEndExcluding": "10.2.8",
"versionStartIncluding": "10.2.0"
},
{
"criteria": "cpe:2.3:o:paloaltonetworks:pan-os:*:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "A6B9B8A6-A4A7-4C14-9D22-50FEF531F15D",
"versionEndExcluding": "11.0.3",
"versionStartIncluding": "11.0.0"
},
{
"criteria": "cpe:2.3:o:paloaltonetworks:pan-os:9.0.17:-:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "CDAE9753-EF8D-4B15-A73C-0EF56FE6C78C"
},
{
"criteria": "cpe:2.3:o:paloaltonetworks:pan-os:9.0.17:h1:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "2A142EE1-E516-4582-9A7E-6E4C74FB3991"
}
],
"operator": "OR"
}
]
}
],
"sourceIdentifier": "psirt@paloaltonetworks.com"
}