CVE-2024-9474
Palo Alto Networks · Published November 18, 2024
7.2
CVSS v3.1
HIGHCISA KEV — Federal agencies must patch by deadline
Actively exploited in the wild
Patch availableGet patch
Description
A privilege escalation vulnerability in Palo Alto Networks PAN-OS software allows a PAN-OS administrator with access to the management web interface to perform actions on the firewall with root privileges. Cloud NGFW and Prisma Access are not impacted by this vulnerability.
Affected Products
- PAN OS < 10.1.14
- PAN OS < 10.2.12
- PAN OS < 11.0.6
- PAN OS < 11.1.5
CVSS Vector
CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H