CVE-2024-9474: PAN-OS: Privilege Escalation (PE) Vulnerability in the Web Management Interface (Severity: MEDIUM)
A privilege escalation vulnerability in Palo Alto Networks PAN-OS software allows a PAN-OS administrator with access to the management web interface to perform actions on the firewall with root privileges.
Cloud NGFW and Prisma Access are not impacted by this vulnerability.
Other sources
A privilege escalation vulnerability in Palo Alto Networks PAN-OS software allows a PAN-OS administrator with access to the management web interface to perform actions on the firewall with root privileges.
This issue is applicable to PAN-OS 10.1, PAN-OS 10.2, PAN-OS 11.0, PAN-OS 11.1, and PAN-OS 11.2 software on PA-Series, VM-Series, and CN-Series firewalls and on Panorama (virtual and M-Series) and WildFire appliances.
Cloud NGFW and Prisma Access are not impacted by this vulnerability.
— Palo Alto Networks
Palo Alto Networks PAN-OS contains an OS command injection vulnerability that allows for privilege escalation through the web-based management interface for several PAN products, including firewalls and VPN concentrators.
— CISA
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
Palo Alto PAN-OSto a version that resolves this vulnerability.Fixed in 11.2.4-h1Fixed in 11.2.0-h1Fixed in 11.2.1-h1Fixed in 11.2.2-h2Fixed in 11.2.3-h3Fixed in 11.1.5-h1Fixed in 11.1.0-h4Fixed in 11.1.1-h2Fixed in 11.1.2-h15Fixed in 11.1.3-h11Fixed in 11.1.4-h7Fixed in 11.0.6-h1Fixed in 11.0.0-h4Fixed in 11.0.5-h2Fixed in 11.0.4-h6Fixed in 11.0.3-h13Fixed in 11.0.2-h5Fixed in 11.0.1-h5Fixed in 10.2.12-h2Fixed in 10.2.0-h4Fixed in 10.2.11-h6Fixed in 10.2.10-h9Fixed in 10.2.9-h16Fixed in 10.2.8-h15Fixed in 10.2.7-h18Fixed in 10.2.6-h6Fixed in 10.2.5-h9Fixed in 10.2.4-h32Fixed in 10.2.3-h14Fixed in 10.2.2-h6Fixed in 10.2.1-h3Fixed in 10.1.14-h6Fixed in 10.1.3-h4Fixed in 10.1.13-h5Fixed in 10.1.12-h3Fixed in 10.1.11-h10Fixed in 10.1.10-h9Fixed in 10.1.9-h14Fixed in 10.1.8-h8Fixed in 10.1.6-h9 - Upgrade
Upgrade
Palo Alto Networks PAN-OSto a version that resolves this vulnerability.Fixed in 10.1.14-h6 - Upgrade
Upgrade
Palo Alto Networks PAN-OSto a version that resolves this vulnerability.Fixed in 10.2.12-h2 - Upgrade
Upgrade
Palo Alto Networks PAN-OSto a version that resolves this vulnerability.Fixed in 11.0.6-h1 - Upgrade
Upgrade
Palo Alto Networks PAN-OSto a version that resolves this vulnerability.Fixed in 11.1.5-h1 - Upgrade
Upgrade
Palo Alto Networks PAN-OSto a version that resolves this vulnerability.Fixed in 11.2.4-h1 - Compensating control
Do not expose the affected PAN-OS management web interface to untrusted networks (including the internet); restrict management interface access to only trusted internal IP addresses per Palo Alto Networks administrative access best practices.
Event History
Frequently Asked Questions
What is the severity of CVE-2024-9474?
CVE-2024-9474 is classified as a privilege escalation vulnerability in Palo Alto Networks PAN-OS software.
How can I fix CVE-2024-9474?
To remediate CVE-2024-9474, update your PAN-OS to a version that is not affected, such as 11.2.4-h1 or later.
Who is affected by CVE-2024-9474?
CVE-2024-9474 affects administrators who access the management web interface of Palo Alto Networks PAN-OS.
Does CVE-2024-9474 impact Cloud NGFW or Prisma Access?
No, CVE-2024-9474 does not impact Palo Alto Networks Cloud NGFW or Prisma Access.
What actions can be performed with the exploit of CVE-2024-9474?
Exploiting CVE-2024-9474 allows a PAN-OS administrator to perform actions on the firewall with root privileges.