CVE-2024-9474: PAN-OS: Privilege Escalation (PE) Vulnerability in the Web Management Interface (Severity: MEDIUM)

Published Nov 18, 2024
·
Updated

A privilege escalation vulnerability in Palo Alto Networks PAN-OS software allows a PAN-OS administrator with access to the management web interface to perform actions on the firewall with root privileges.

Cloud NGFW and Prisma Access are not impacted by this vulnerability.

Other sources

A privilege escalation vulnerability in Palo Alto Networks PAN-OS software allows a PAN-OS administrator with access to the management web interface to perform actions on the firewall with root privileges.

This issue is applicable to PAN-OS 10.1, PAN-OS 10.2, PAN-OS 11.0, PAN-OS 11.1, and PAN-OS 11.2 software on PA-Series, VM-Series, and CN-Series firewalls and on Panorama (virtual and M-Series) and WildFire appliances.

Cloud NGFW and Prisma Access are not impacted by this vulnerability.

Palo Alto Networks

Palo Alto Networks PAN-OS contains an OS command injection vulnerability that allows for privilege escalation through the web-based management interface for several PAN products, including firewalls and VPN concentrators.

CISA

Affected Software

17 affected componentsFixes available
Palo Alto Networks Cloud NGFW
Palo Alto Networks PAN-OS<11.2.4-h1, =11.2.0, <11.1.5-h1, =11.1.0, <11.0.6-h1, =11.0.0, <10.2.12-h2, =10.2.0, <10.1.14-h6, =10.1.0
11.2.4-h111.2.0-h111.2.1-h111.2.2-h211.2.3-h311.1.5-h111.1.0-h411.1.1-h211.1.2-h1511.1.3-h1111.1.4-h711.0.6-h111.0.0-h411.0.5-h211.0.4-h611.0.3-h1311.0.2-h511.0.1-h510.2.12-h210.2.0-h410.2.11-h610.2.10-h910.2.9-h1610.2.8-h1510.2.7-h1810.2.6-h610.2.5-h910.2.4-h3210.2.3-h1410.2.2-h610.2.1-h310.1.14-h610.1.3-h410.1.13-h510.1.12-h310.1.11-h1010.1.10-h910.1.9-h1410.1.8-h810.1.6-h9
Palo Alto Networks Prisma Access
Palo Alto Networks PAN-OS
Palo Alto Networks PAN-OS>=10.1.0<10.1.14
Palo Alto Networks PAN-OS>=10.2.0<10.2.12
Palo Alto Networks PAN-OS>=11.0.0<11.0.6
Palo Alto Networks PAN-OS>=11.1.0<11.1.5
Palo Alto Networks PAN-OS>=11.2.0<11.2.4
Palo Alto Networks PAN-OS=10.1.14
Palo Alto Networks PAN-OS=10.1.14-h2
Palo Alto Networks PAN-OS=10.1.14-h4
Palo Alto Networks PAN-OS=10.2.12
Palo Alto Networks PAN-OS=10.2.12-h1
Palo Alto Networks PAN-OS=11.0.6
Palo Alto Networks PAN-OS=11.1.5
Palo Alto Networks PAN-OS=11.2.4

Remediation

Recommended actions to resolve this vulnerability, in priority order.

  1. Upgrade

    Upgrade Palo Alto PAN-OS to a version that resolves this vulnerability.

    Fixed in 11.2.4-h1Fixed in 11.2.0-h1Fixed in 11.2.1-h1Fixed in 11.2.2-h2Fixed in 11.2.3-h3Fixed in 11.1.5-h1Fixed in 11.1.0-h4Fixed in 11.1.1-h2Fixed in 11.1.2-h15Fixed in 11.1.3-h11Fixed in 11.1.4-h7Fixed in 11.0.6-h1Fixed in 11.0.0-h4Fixed in 11.0.5-h2Fixed in 11.0.4-h6Fixed in 11.0.3-h13Fixed in 11.0.2-h5Fixed in 11.0.1-h5Fixed in 10.2.12-h2Fixed in 10.2.0-h4Fixed in 10.2.11-h6Fixed in 10.2.10-h9Fixed in 10.2.9-h16Fixed in 10.2.8-h15Fixed in 10.2.7-h18Fixed in 10.2.6-h6Fixed in 10.2.5-h9Fixed in 10.2.4-h32Fixed in 10.2.3-h14Fixed in 10.2.2-h6Fixed in 10.2.1-h3Fixed in 10.1.14-h6Fixed in 10.1.3-h4Fixed in 10.1.13-h5Fixed in 10.1.12-h3Fixed in 10.1.11-h10Fixed in 10.1.10-h9Fixed in 10.1.9-h14Fixed in 10.1.8-h8Fixed in 10.1.6-h9
  2. Upgrade

    Upgrade Palo Alto Networks PAN-OS to a version that resolves this vulnerability.

    Fixed in 10.1.14-h6
  3. Upgrade

    Upgrade Palo Alto Networks PAN-OS to a version that resolves this vulnerability.

    Fixed in 10.2.12-h2
  4. Upgrade

    Upgrade Palo Alto Networks PAN-OS to a version that resolves this vulnerability.

    Fixed in 11.0.6-h1
  5. Upgrade

    Upgrade Palo Alto Networks PAN-OS to a version that resolves this vulnerability.

    Fixed in 11.1.5-h1
  6. Upgrade

    Upgrade Palo Alto Networks PAN-OS to a version that resolves this vulnerability.

    Fixed in 11.2.4-h1
  7. Compensating control

    Do not expose the affected PAN-OS management web interface to untrusted networks (including the internet); restrict management interface access to only trusted internal IP addresses per Palo Alto Networks administrative access best practices.

Event History

Nov 18, 2024
CVE Published
via CISA·12:00 AM
Known Exploited
via CISA·12:00 AM
Known Ransomware
via CISA·12:00 AM
Data Sourced
via CISA·12:00 AM
RemedyDescriptionAffected Software
Advisory Published
via Palo Alto Networks·02:20 PM
CVE Published
via MITRE·03:48 PM
Data Sourced
via MITRE·03:48 PM
DescriptionWeakness
Data Sourced
via NVD·04:15 PM
DescriptionSeverityWeaknessAffected Software
News Published
via BleepingComputer·08:50 PM
News Published
via BleepingComputer·08:51 PM
Nov 19, 2024
News Published
via The Register·03:29 PM
News Published
via The Register·03:31 PM
News Published
via BleepingComputer·09:18 PM
Nov 21, 2024
Advisory Published
via Palo Alto Networks·01:40 AM
News Published
via BleepingComputer·07:46 PM
Nov 22, 2024
News Published
via The Register·09:27 PM
Feb 14, 2025
News Published
via BleepingComputer·09:20 PM
Feb 19, 2025
News Published
via The Register·12:15 AM
News Published
via BleepingComputer·03:38 PM
News Published
via Dark Reading·04:39 PM
Feb 20, 2025
News Published
via Dark Reading·12:41 AM
Feb 21, 2025
News Published
via BleepingComputer·03:57 PM
Nov 20, 2025
News Published
via BleepingComputer·05:08 PM
Jan 15, 2026
News Published
via BleepingComputer·09:02 AM

Peer vulnerabilities

Found alongside the following vulnerabilities.

Free Weekly Intel

Don't miss critical vulnerabilities

Join thousands of security professionals who receive our weekly digest of trending CVEs, zero-days, and exploited vulnerabilities.

No spam. Unsubscribe anytime.

Frequently Asked Questions

1

What is the severity of CVE-2024-9474?

CVE-2024-9474 is classified as a privilege escalation vulnerability in Palo Alto Networks PAN-OS software.

2

How can I fix CVE-2024-9474?

To remediate CVE-2024-9474, update your PAN-OS to a version that is not affected, such as 11.2.4-h1 or later.

3

Who is affected by CVE-2024-9474?

CVE-2024-9474 affects administrators who access the management web interface of Palo Alto Networks PAN-OS.

4

Does CVE-2024-9474 impact Cloud NGFW or Prisma Access?

No, CVE-2024-9474 does not impact Palo Alto Networks Cloud NGFW or Prisma Access.

5

What actions can be performed with the exploit of CVE-2024-9474?

Exploiting CVE-2024-9474 allows a PAN-OS administrator to perform actions on the firewall with root privileges.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203