CVE-2024-5916Medium

CVE-2024-5916 PAN-OS: Cleartext Exposure of External System Secrets

Published
August 14, 2024
Last Modified
April 30, 2025

🔗 CVE IDs covered (1)

📋 Description

An information exposure vulnerability in Palo Alto Networks PAN-OS software enables a local system administrator to unintentionally disclose secrets, passwords, and tokens of external systems. A read-only administrator who has access to the config log, can read secrets, passwords, and tokens to external systems.

🎯 Affected products3

  • Cloud NGFW
  • PAN-OS
  • Prisma Access

✅ Remediation

This issue is fixed in PAN-OS 10.2.8, PAN-OS 11.0.4, and all later PAN-OS versions. This issue is fixed in Cloud NGFW on or after 8/15 on Azure, Cloud NGFW on or after 8/23 on AWS, and all later Cloud NGFW versions. You should also revoke the secrets, passwords, and tokens that are configured in all server profiles of affected PAN-OS firewalls (Device > Server Profiles) after upgrading PAN-OS. Workarounds and mitigations: No known workarounds or mitigations exist for this issue.

🔗 References (1)