CVE-2024-9474

Confirmed PUBLISHED

PAN-OS: Privilege Escalation (PE) Vulnerability in the Web Management Interface

Palo Alto Networks · Cloud NGFW, PAN-OS, Prisma Access
Exploited in the wild Used in malware PoC available

Recommended Action

Prioritize remediation. Validate affected assets and apply vendor fixes on an accelerated timeline.

Confidence
Confirmed
Exploitation Status
Exploited in the wild
Observed in Sensors
No
Attempts (30d)
Unique Attacker IPs
CISA KEV
In CISA KEV
CVSS / EPSS
6.9 Medium EPSS 94.8%

At a Glance

A privilege escalation vulnerability in Palo Alto Networks PAN-OS software allows a PAN-OS administrator with access to the management web interface to perform actions on the firewall with root privileges. Cloud NGFW and Prisma Access are not impacted by this vulnerability.

edge cisa metasploit nessus_scanner nuclei_scanner malware
CVE Published
Nov 18, 2024
Exploitation Reported
Nov 18, 2024
CVSS
6.9 Medium
EPSS
94.8%
Remote Low complexity No user interaction

Affected Versions

32 version rows · page 1 of 2

Vendor Product Version Status
paloaltonetworks
pan-os

11.2.0 to < 11.2.4-h1

Affected
paloaltonetworks
pan-os

11.1.0 to < 11.1.5-h1

Affected
paloaltonetworks
pan-os

11.0.0 to < 11.0.6-h1

Affected
paloaltonetworks
pan-os

10.2.0 to < 10.2.12-h2

Affected
paloaltonetworks
pan-os

10.1.0 to < 10.1.14-h6

Affected
paloaltonetworks
pan-os

11.2.0 to < 11.2.4-h1

Affected
paloaltonetworks
pan-os

11.1.0 to < 11.1.5-h1

Affected
paloaltonetworks
pan-os

11.0.0 to < 11.0.6-h1

Affected
paloaltonetworks
pan-os

10.2.0 to < 10.2.12-h2

Affected
paloaltonetworks
pan-os

10.1.0 to < 10.1.14-h6

Affected
paloaltonetworks
pan-os

11.2.0 to < 11.2.4-h1

Affected
paloaltonetworks
pan-os

11.1.0 to < 11.1.5-h1

Affected
paloaltonetworks
pan-os

11.0.0 to < 11.0.6-h1

Affected
paloaltonetworks
pan-os

10.2.0 to < 10.2.12-h2

Affected
paloaltonetworks
pan-os

10.1.0 to < 10.1.14-h6

Affected
paloaltonetworks
pan-os

11.2.0 to < 11.2.4-h1

Affected
paloaltonetworks
pan-os

11.1.0 to < 11.1.5-h1

Affected
paloaltonetworks
pan-os

11.0.0 to < 11.0.6-h1

Affected
paloaltonetworks
pan-os

10.2.0 to < 10.2.12-h2

Affected
paloaltonetworks
pan-os

10.1.0 to < 10.1.14-h6

Affected
paloaltonetworks
pan-os

11.2.0 to < 11.2.4-h1

Affected
paloaltonetworks
pan-os

11.1.0 to < 11.1.5-h1

Affected
paloaltonetworks
pan-os

11.0.0 to < 11.0.6-h1

Affected
paloaltonetworks
pan-os

10.2.0 to < 10.2.12-h2

Affected
paloaltonetworks
pan-os

10.1.0 to < 10.1.14-h6

Affected

CVE References

Recommended Actions

  • Prioritize remediation. Validate affected assets and apply vendor fixes on an accelerated timeline.
  • Check enrichment artifacts for scanner coverage and available PoCs before rolling remediation validation.
  • Use the Pro API to automate enrichment, telemetry, and workflow delivery for VM, SOC, and CTI pipelines.