CVE-2024-9474

A privilege escalation vulnerability in Palo Alto Networks PAN-OS software allows a PAN-OS administrator with access to the management web interface to perform actions on the firewall with root privileges.

Cloud NGFW and Prisma Access are not impacted by this vulnerability.
OS Command Injection
ProviderTypeBase ScoreAtk. VectorAtk. ComplexityPriv. RequiredVector
NISTNIST
7.2 HIGH
NETWORK
LOW
HIGH
CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H
palo_altoCNA
---
---
CISA-ADPADP
---
---
CVEADP
---
---
Base Score
CVSS 3.x
EPSS Score
Percentile: 99%
VendorProductVersion
paloaltonetworkspan-os
10.1.0 ≤
𝑥
< 10.1.14
paloaltonetworkspan-os
10.2.0 ≤
𝑥
< 10.2.12
paloaltonetworkspan-os
11.0.0 ≤
𝑥
< 11.0.6
paloaltonetworkspan-os
11.1.0 ≤
𝑥
< 11.1.5
paloaltonetworkspan-os
11.2.0 ≤
𝑥
< 11.2.4
paloaltonetworkspan-os
10.1.14
paloaltonetworkspan-os
10.1.14:h2
paloaltonetworkspan-os
10.1.14:h4
paloaltonetworkspan-os
10.2.12
paloaltonetworkspan-os
10.2.12:h1
paloaltonetworkspan-os
11.0.6
paloaltonetworkspan-os
11.1.5
paloaltonetworkspan-os
11.2.4
𝑥
= Vulnerable software versions