HIGH

CVE-2024-9474

Paloaltonetworks Pan Os 2024-11-18 CVSS v3.1
CVSS
7.2
KEV

Description

A privilege escalation vulnerability in Palo Alto Networks PAN-OS software allows a PAN-OS administrator with access to the management web interface to perform actions on the firewall with root privileges.

Cloud NGFW and Prisma Access are not impacted by this vulnerability.

Summary dbcve.org

A privilege escalation vulnerability in Palo Alto Networks PAN-OS allows authenticated administrators with access to the management web interface to execute commands with root privileges. This is a vertical privilege escalation from admin-level to root-level access on the firewall.

Mitigation

Apply the vendor-supplied patch for PAN-OS when available. Until patched, strictly limit administrative access to the management interface to trusted personnel and monitor for anomalous admin activities.

Proof of Concept

Weakness (CWE)

CWE-78 OS Command Injection

EPSS Score

94.7%
Probability of exploitation in next 30 days
99.9th percentile

References

View on dbcve.org
Base CVE data derived from NVD (public domain). Enrichment by dbcve.org (CC-BY-4.0). Fetched via API.
Back to CVE