CVE-2024-9474: Palo Alto Networks PAN-OS Management Interface OS Command Injection Vulnerability
High severity, CVSS 7.2. Actively exploited: in CISA KEV since 2024-11-18. EPSS: 94.8% chance of exploitation in the next 30 days.
A privilege escalation vulnerability in Palo Alto Networks PAN-OS software allows a PAN-OS administrator with access to the management web interface to perform actions on the firewall with root privileges. Cloud NGFW and Prisma Access are not impacted by this vulnerability.
Affected products
- Palo Alto Networks PAN-OS: from 10.1.0, before 10.1.14 (fixed in 10.1.14); from 10.2.0, before 10.2.12 (fixed in 10.2.12); from 11.0.0, before 11.0.6 (fixed in 11.0.6); from 11.1.0, before 11.1.5 (fixed in 11.1.5); from 11.2.0, before 11.2.4 (fixed in 11.2.4); version 10.1.14 only; …
Published 2024-11-18. Last modified 2026-08-04.