THREAT OPS › CVEs › CVE-2024-9474
CVE-2024-9474 — Palo Alto Networks PAN-OS Management Interface OS Command Injection Vulnerability
Palo Alto Networks PAN-OS contains an OS command injection vulnerability that allows for privilege escalation through the web-based management interface for several PAN products, including firewalls and VPN concentrators.
Vulnerability details
- Affected productsPAN-OS
- KEV remediation due2024-12-09
Related reporting
- [NVD] CVE-2024-0012 (CRITICAL 9.8) — An authentication bypass in Palo Alto Networks PAN-OS software enables an unauthenticated attacker with network access to the management web interface to gain PAN-OS administrator privileges to perform administrative actions, tamper with the configuration, or exploit other authennvd
- [NVD] CVE-2024-9474 (HIGH 7.2) — A privilege escalation vulnerability in Palo Alto Networks PAN-OS software allows a PAN-OS administrator with access to the management web interface to perform actions on the firewall with root privileges. Cloud NGFW and Prisma Access are not impacted by this vulnerability.nvd