Skip to content
VulniPulse
Highest advisory severityCritical Exploited CISA KEV 1 vendor · 2 advisories

CVE-2024-9474

CVE-2024-9474: 2 tracked advisory records across Palo Alto. CISA KEV listed; exploitation observed. Compare vendor sources and published fix guidance.

Compare the source-linked records below. Ratings and product/version details belong to each advisory; they are not a single CVE-wide score or proof that every listed product is affected. How VulniPulse collects and checks evidence.

Vendor advisory comparison

Palo Alto

2 advisories
  • Advisory severityCritical9.3

    Critical [CVE-2024-0012 +1] PAN-OS: Authentication Bypass in the Management Web Interface (PAN-SA-2024-0015)

    CVE-2024-0012Source published Source updated

    This bulletin covers 2 CVEs. The products, versions, score and guidance below describe the bulletin; check its source for applicability to this specific CVE.

    An authentication bypass in Palo Alto Networks PAN-OS software enables an unauthenticated attacker with network access to the management web interface to gain PAN-OS administrator privileges to perform administrative actions, tamper with the configuration, or exploit other authenticated privilege escalation vulnerabilities like CVE-2024-9474. The risk of this issue is greatly reduced if you secure access to the management web interface by restricting access to only trusted internal IP addresses according to our recommended best practice deployment guidelines. This issue is applicable only to PAN-OS 10.2, PAN-OS 11.0, PAN-OS 11.1, and PAN-OS 11.2 software on PA-Series, VM-Series, and CN-Series firewalls and on Panorama (virtual and M-Series). Cloud NGFW and Prisma Access are not impacted…

    Affected products in this advisory
    • PAN-OS
    Source-reported affected versions
    • PAN-OS 11.2: < 11.2.0-h1< 11.2.1-h1< 11.2.2-h2< 11.2.3-h3< 11.2.4-h1
    • PAN-OS 11.1: < 11.1.0-h4< 11.1.1-h2< 11.1.2-h15< 11.1.3-h11< 11.1.4-h7< 11.1.5-h1
    • PAN-OS 11.0: < 11.0.0-h4< 11.0.1-h5< 11.0.2-h5< 11.0.3-h13< 11.0.4-h6< 11.0.5-h2< 11.0.6-h1
    • PAN-OS 10.2: < 10.2.0-h4< 10.2.1-h3< 10.2.2-h6< 10.2.3-h14< 10.2.4-h32< 10.2.5-h9< 10.2.6-h6< 10.2.7-h18< 10.2.8-h15< 10.2.9-h16< 10.2.10-h9< 10.2.11-h6< 10.2.12-h2
    Source-reported fixed versions
    • PAN-OS 11.2: >= 11.2.0-h1>= 11.2.1-h1>= 11.2.2-h2>= 11.2.3-h3>= 11.2.4-h1
    • PAN-OS 11.1: >= 11.1.0-h4>= 11.1.1-h2>= 11.1.2-h15>= 11.1.3-h11>= 11.1.4-h7>= 11.1.5-h1
    • PAN-OS 11.0: >= 11.0.0-h4>= 11.0.1-h5>= 11.0.2-h5>= 11.0.3-h13>= 11.0.4-h6>= 11.0.5-h2>= 11.0.6-h1
    • PAN-OS 10.2: >= 10.2.0-h4>= 10.2.1-h3>= 10.2.2-h6>= 10.2.3-h14>= 10.2.4-h32>= 10.2.5-h9>= 10.2.6-h6>= 10.2.7-h18>= 10.2.8-h15>= 10.2.9-h16>= 10.2.10-h9>= 10.2.11-h6>= 10.2.12-h2
    Mitigation guidance
    • We strongly recommend that you secure access to your management interface following the instructions in the workarounds section below.
    • This issue is fixed in PAN-OS 10.2.12-h2, PAN-OS 11.0.6-h1, PAN-OS 11.1.5-h1, PAN-OS 11.2.4-h1, and all later PAN-OS versions.
    • In addition, in an attempt to provide the most seamless upgrade path for our customers, we are making fixes available for other TAC-preferred and commonly deployed maintenance releases.
    Workarounds
    • Recommended mitigation—The vast majority of firewalls already follow Palo Alto Networks and industry best practices.
    • However, if you haven’t already, we strongly recommend that you secure access to your management interface according to our best practice deployment guidelines.
    • Specifically, you should restrict access to the management interface to only trusted internal IP addresses to prevent external access from the internet.
    • Additionally, if you have a Threat Prevention subscription, you can block these attacks using Threat IDs 95746, 95747, 95752, 95753, 95759, and 95763 (available in Applications and Threats content version 8915-9075 and later).

    1 more entries in the full advisory.

  • Advisory severityMedium6.9

    Medium [CVE-2024-9474] PAN-OS: Privilege Escalation (PE) Vulnerability in the Web Management Interface

    CVE-2024-9474Source published Source updated

    A privilege escalation vulnerability in Palo Alto Networks PAN-OS software allows a PAN-OS administrator with access to the management web interface to perform actions on the firewall with root privileges. This issue is applicable to PAN-OS 10.1, PAN-OS 10.2, PAN-OS 11.0, PAN-OS 11.1, and PAN-OS 11.2 software on PA-Series, VM-Series, and CN-Series firewalls and on Panorama (virtual and M-Series) and WildFire appliances. Cloud NGFW and Prisma Access are not impacted by this vulnerability.

    Affected products in this advisory
    • PAN-OS
    Source-reported affected versions
    • PAN-OS < 11.2.4-h1
    • PAN-OS < 11.1.5-h1
    • PAN-OS < 11.0.6-h1
    • PAN-OS < 10.2.12-h2

    1 more entries in the full advisory.

    Source-reported fixed versions
    • PAN-OS >= 11.2.4-h1
    • PAN-OS >= 11.2.0-h1
    • PAN-OS >= 11.2.1-h1
    • PAN-OS >= 11.2.2-h2

    16 more entries in the full advisory.

    Mitigation guidance
    • This issue is fixed in PAN-OS 10.1.14-h6, PAN-OS 10.2.12-h2, PAN-OS 11.0.6-h1, PAN-OS 11.1.5-h1, PAN-OS 11.2.4-h1, and all later PAN-OS versions.
    • In addition, in an attempt to provide the most seamless upgrade path for our customers, we are making fixes available for other TAC-preferred and commonly deployed maintenance releases.
    Workarounds
    • Recommended mitigation—The vast majority of firewalls already follow Palo Alto Networks and industry best practices.
    • However, if you haven’t already, we strongly recommend that you secure access to your management interface according to our best practice deployment guidelines.
    • Specifically, you should restrict access to the management interface to only trusted internal IP addresses to prevent external access from the internet.
    • Review information about how to secure management access to your Palo Alto Networks firewalls:

Android app · Google Play

Monitor future Palo Alto CVEs from your phone.

Choose a whole vendor or a precise platform, then receive matching security advisories by phone notification, email, or both. Coverage follows 34 official vendor sources and 160+ reviewed platform categories.

Matching phone alertsOptional email delivery