← Back

CVE-2024-9474

Published: Nov 18, 2024Modified: Jun 17, 2026CISA KEV

JSON object

Loading...
6.9
Vector
CVSS:4.0/AV:N/AC:L/AT:N/PR:H/UI:N/VC:N/VI:H/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:N/R:U/V:C/RE:H/U:Red
Show more
CVSS:4.0/AV:N/AC:L/AT:N/PR:H/UI:N/VC:N/VI:H/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:N/R:U/V:C/RE:H/U:RedShow less
Source: psirt@paloaltonetworks.com (Secondary)

Description

A privilege escalation vulnerability in Palo Alto Networks PAN-OS software allows a PAN-OS administrator with access to the management web interface to perform actions on the firewall with root privileges. Cloud NGFW and Prisma Access are not impacted by this vulnerability.

Affected (13)

Pan Os
Configuration A
13 vulnerable
Vulnerable SoftwareAffected Versions
Paloaltonetworks
From 10.1.0 to 10.1.14
From 10.2.0 to 10.2.12
From 11.0.0 to 11.0.6
From 11.1.0 to 11.1.5
From 11.2.0 to 11.2.4
Version 10.1.14
Version 10.1.14 h2
Version 10.1.14 h4
Version 10.2.12
Version 10.2.12 h1
Version 11.0.6
Version 11.1.5
Version 11.2.4

References (5)

Source: psirt@paloaltonetworks.com
Vendor Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Press/Media CoverageVendor Advisory
Source: 134c704f-9b21-4f2e-91b3-4a467353bcc0
Exploit
Source: 134c704f-9b21-4f2e-91b3-4a467353bcc0
ExploitThird Party Advisory
Source: 134c704f-9b21-4f2e-91b3-4a467353bcc0
US Government Resource

Timeline

No history available yet.