Medium [CVE-2024-9474] PAN-OS: Privilege Escalation (PE) Vulnerability in the Web Management Interface
This medium-severity Palo Alto Networks advisory covers CVE-2024-9474 affecting PAN-OS.
Android app · Google Play
Monitor future Palo Alto Networks CVEs from your phone.
Choose a whole vendor or a precise platform, then receive matching security advisories by phone notification, email, or both. Coverage follows 32 official vendor sources and 160+ reviewed platform categories.
Summary
A privilege escalation vulnerability in Palo Alto Networks PAN-OS software allows a PAN-OS administrator with access to the management web interface to perform actions on the firewall with root privileges.
This issue is applicable to PAN-OS 10.1, PAN-OS 10.2, PAN-OS 11.0, PAN-OS 11.1, and PAN-OS 11.2 software on PA-Series, VM-Series, and CN-Series firewalls and on Panorama (virtual and M-Series) and WildFire appliances. Cloud NGFW and Prisma Access are not impacted by this vulnerability.
CISA Known Exploited Vulnerability
- Listed:
- Nov 18, 2024 · federal remediation due Dec 9, 2024
- Required action:
- Apply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable. Additionally, the management interfaces for affected devices should not be exposed to untrusted networks, including the internet.
- Ransomware use:
- Known
KEV is a prioritization signal from CISA — remediation detail still comes from the vendor advisory.
- PAN-OS < 11.2.4-h1
- PAN-OS < 11.1.5-h1
- PAN-OS < 11.0.6-h1
- PAN-OS < 10.2.12-h2
- PAN-OS < 10.1.14-h6
Official advisory · high-confidence parse· fetched 1 hour ago·verify at source
- PAN-OS >= 11.2.4-h1
- PAN-OS >= 11.2.0-h1
- PAN-OS >= 11.2.1-h1
- PAN-OS >= 11.2.2-h2
- PAN-OS >= 11.2.3-h3
- PAN-OS >= 11.1.5-h1
- PAN-OS >= 11.1.0-h4
- PAN-OS >= 11.1.1-h2
- PAN-OS >= 11.1.2-h15
- PAN-OS >= 11.1.3-h11
- PAN-OS >= 11.1.4-h7
- PAN-OS >= 11.0.6-h1
- PAN-OS >= 11.0.0-h4
- PAN-OS >= 11.0.5-h2
- PAN-OS >= 11.0.4-h6
- PAN-OS >= 11.0.3-h13
- PAN-OS >= 11.0.2-h5
- PAN-OS >= 11.0.1-h5
- PAN-OS >= 10.2.12-h2
- PAN-OS >= 10.2.0-h4
Official advisory · high-confidence parse· fetched 1 hour ago·verify at source
Mitigation checklist
- This issue is fixed in PAN-OS 10.1.14-h6, PAN-OS 10.2.12-h2, PAN-OS 11.0.6-h1, PAN-OS 11.1.5-h1, PAN-OS 11.2.4-h1, and all later PAN-OS versions.
- In addition, in an attempt to provide the most seamless upgrade path for our customers, we are making fixes available for other TAC-preferred and commonly deployed maintenance releases.
- Recommended mitigation—The vast majority of firewalls already follow Palo Alto Networks and industry best practices.
- However, if you haven’t already, we strongly recommend that you secure access to your management interface according to our best practice deployment guidelines.
- Specifically, you should restrict access to the management interface to only trusted internal IP addresses to prevent external access from the internet.
- Review information about how to secure management access to your Palo Alto Networks firewalls:
Official advisory · high-confidence parse· fetched 1 hour ago·verify at source
Discussion(0)
No comments yet. Share field notes, upgrade gotchas, or questions — verify against the vendor advisory before acting on community advice.
Sign in to join the discussion.