CVE-2024-9471: PAN-OS: Privilege Escalation (PE) Vulnerability in XML API (Severity: MEDIUM)
A privilege escalation (PE) vulnerability in the XML API of Palo Alto Networks PAN-OS software enables an authenticated PAN-OS administrator with restricted privileges to use a compromised XML API key to perform actions as a higher privileged PAN-OS administrator beyond what the XML API permits.
Other sources
A privilege escalation (PE) vulnerability in the XML API of Palo Alto Networks PAN-OS software enables an authenticated PAN-OS administrator with restricted privileges to use a compromised XML API key to perform actions as a higher privileged PAN-OS administrator. For example, an administrator with "Virtual system administrator (read-only)" access could use an XML API key of a "Virtual system administrator" to perform write operations on the virtual system configuration even though they should be limited to read-only operations.
— NVD
Affected Software
Remediation
Information
Mitigation
Event History
Frequently Asked Questions
What is the severity of CVE-2024-9471?
CVE-2024-9471 is categorized as a privilege escalation vulnerability affecting Palo Alto Networks PAN-OS.
How do I fix CVE-2024-9471?
To remediate CVE-2024-9471, upgrade your PAN-OS to the latest patched version provided by Palo Alto Networks.
Which versions of PAN-OS are affected by CVE-2024-9471?
CVE-2024-9471 affects PAN-OS versions 10.1.10 and earlier, 10.2.8, and 11.0.3 and earlier.
Can CVE-2024-9471 be exploited remotely?
CVE-2024-9471 requires an authenticated user with restricted privileges to exploit the vulnerability.
What impact does CVE-2024-9471 have on my network?
Exploitation of CVE-2024-9471 allows an attacker to escalate their privileges and perform higher-privileged actions on the PAN-OS.