CVE-2024-9474 is a critical privilege escalation vulnerability in Palo Alto Networks PAN-OS software, allowing an authenticated administrator with management web interface access to execute commands with root privileges. This high-severity flaw (CVSS 7.2) is easily exploitable over the network with high impact on confidentiality, integrity, and availability. It is actively exploited in the wild, including in ransomware campaigns, with public exploit modules and significant community discussion and media coverage underscoring its immediate threat. Cloud NGFW and Prisma Access are not affected.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
>= 10.1.0, < 10.1.14CPE matchmatch criteria | cpe:2.3:o:paloaltonetworks:pan-os:*:*:*:*:*:*:*:* | ||
>= 10.2.0, < 10.2.12CPE matchmatch criteria | cpe:2.3:o:paloaltonetworks:pan-os:*:*:*:*:*:*:*:* | ||
>= 11.0.0, < 11.0.6CPE matchmatch criteria | cpe:2.3:o:paloaltonetworks:pan-os:*:*:*:*:*:*:*:* | ||
>= 11.1.0, < 11.1.5CPE matchmatch criteria | cpe:2.3:o:paloaltonetworks:pan-os:*:*:*:*:*:*:*:* | ||
>= 11.2.0, < 11.2.4CPE matchmatch criteria | cpe:2.3:o:paloaltonetworks:pan-os:*:*:*:*:*:*:*:* |
CVSS version used by this source: 4.0
CVSS:4.0/AV:N/AC:L/AT:N/PR:H/UI:N/VC:N/VI:H/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:N/R:U/V:C/RE:H/U:Red
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.1 Mastodon, and 0.3 GitHub mentions.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.