{ "id": "CVE-2024-2433", "sourceIdentifier": "psirt@paloaltonetworks.com", "published": "2024-03-13T18:15:08.893", "lastModified": "2024-03-13T18:15:58.530", "vulnStatus": "Awaiting Analysis", "cveTags": [], "descriptions": [ { "lang": "en", "value": "An improper authorization vulnerability in Palo Alto Networks Panorama software enables an authenticated read-only administrator to upload files using the web interface and completely fill one of the disk partitions with those uploaded files, which prevents the ability to log into the web interface or to download PAN-OS, WildFire, and content images. \n\n\n\nThis issue affects only the web interface of the management plane; the dataplane is unaffected.\n" }, { "lang": "es", "value": "Una vulnerabilidad de autorizaci\u00f3n inadecuada en el software Panorama de Palo Alto Networks permite que un administrador autenticado de solo lectura cargue archivos utilizando la interfaz web y llene completamente una de las particiones del disco con esos archivos cargados, lo que impide iniciar sesi\u00f3n en la interfaz web o descargarlos. PAN-OS, WildFire e im\u00e1genes de contenido. Este problema afecta \u00fanicamente a la interfaz web del plano de gesti\u00f3n; el plano de datos no se ve afectado." } ], "metrics": { "cvssMetricV31": [ { "source": "psirt@paloaltonetworks.com", "type": "Secondary", "cvssData": { "version": "3.1", "vectorString": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:L", "attackVector": "NETWORK", "attackComplexity": "LOW", "privilegesRequired": "LOW", "userInteraction": "NONE", "scope": "UNCHANGED", "confidentialityImpact": "NONE", "integrityImpact": "NONE", "availabilityImpact": "LOW", "baseScore": 4.3, "baseSeverity": "MEDIUM" }, "exploitabilityScore": 2.8, "impactScore": 1.4 } ] }, "weaknesses": [ { "source": "psirt@paloaltonetworks.com", "type": "Secondary", "description": [ { "lang": "en", "value": "CWE-269" } ] } ], "references": [ { "url": "https://security.paloaltonetworks.com/CVE-2024-2433", "source": "psirt@paloaltonetworks.com" } ] }