{"resultsPerPage":1,"startIndex":0,"totalResults":1,"format":"NVD_CVE","version":"2.0","timestamp":"2026-09-29T22:14:05.517","vulnerabilities":[{"cve":{"id":"CVE-2024-9474","sourceIdentifier":"psirt@paloaltonetworks.com","published":"2024-11-18T16:15:29.780","lastModified":"2026-08-04T05:16:32.247","vulnStatus":"Analyzed","cveTags":[],"descriptions":[{"lang":"en","value":"A privilege escalation vulnerability in Palo Alto Networks PAN-OS software allows a PAN-OS administrator with access to the management web interface to perform actions on the firewall with root privileges.\n\nCloud NGFW and Prisma Access are not impacted by this vulnerability."},{"lang":"es","value":"Una vulnerabilidad de escalada de privilegios en el software PAN-OS de Palo Alto Networks permite que un administrador de PAN-OS con acceso a la interfaz web de administración realice acciones en el firewall con privilegios de superusuario. Cloud NGFW y Prisma Access no se ven afectados por esta vulnerabilidad."}],"affected":[{"source":"psirt@paloaltonetworks.com","affectedData":[{"vendor":"Palo Alto Networks","product":"Cloud NGFW","defaultStatus":"unaffected","versions":[{"version":"All","status":"unaffected"}]},{"vendor":"Palo Alto Networks","product":"PAN-OS","defaultStatus":"unaffected","versions":[{"version":"11.2.0","lessThan":"11.2.4-h1","versionType":"custom","status":"affected","changes":[{"at":"11.2.4-h1","status":"unaffected"}]},{"version":"11.1.0","lessThan":"11.1.5-h1","versionType":"custom","status":"affected","changes":[{"at":"11.1.5-h1","status":"unaffected"}]},{"version":"11.0.0","lessThan":"11.0.6-h1","versionType":"custom","status":"affected","changes":[{"at":"11.0.6-h1","status":"unaffected"}]},{"version":"10.2.0","lessThan":"10.2.12-h2","versionType":"custom","status":"affected","changes":[{"at":"10.2.12-h2","status":"unaffected"}]},{"version":"10.1.0","lessThan":"10.1.14-h6","versionType":"custom","status":"affected","changes":[{"at":"10.1.14-h6","status":"unaffected"}]}]},{"vendor":"Palo Alto Networks","product":"Prisma Access","defaultStatus":"unaffected","versions":[{"version":"All","status":"unaffected"}]}]},{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","affectedData":[{"vendor":"paloaltonetworks","product":"pan-os","defaultStatus":"unknown","cpes":["cpe:2.3:o:paloaltonetworks:pan-os:-:*:*:*:*:*:*:*"],"versions":[{"version":"11.2.0","lessThan":"11.2.4-h1","versionType":"custom","status":"affected"},{"version":"11.1.0","lessThan":"11.1.5-h1","versionType":"custom","status":"affected"},{"version":"11.0.0","lessThan":"11.0.6-h1","versionType":"custom","status":"affected"},{"version":"10.2.0","lessThan":"10.2.12-h2","versionType":"custom","status":"affected"},{"version":"10.1.0","lessThan":"10.1.14-h6","versionType":"custom","status":"affected"}]},{"vendor":"paloaltonetworks","product":"pan-os","defaultStatus":"unknown","cpes":["cpe:2.3:o:paloaltonetworks:pan-os:-:*:*:*:*:*:*:*"],"versions":[{"version":"11.2.0","lessThan":"11.2.4-h1","versionType":"custom","status":"affected"},{"version":"11.1.0","lessThan":"11.1.5-h1","versionType":"custom","status":"affected"},{"version":"11.0.0","lessThan":"11.0.6-h1","versionType":"custom","status":"affected"},{"version":"10.2.0","lessThan":"10.2.12-h2","versionType":"custom","status":"affected"},{"version":"10.1.0","lessThan":"10.1.14-h6","versionType":"custom","status":"affected"}]},{"vendor":"paloaltonetworks","product":"pan-os","defaultStatus":"unknown","cpes":["cpe:2.3:o:paloaltonetworks:pan-os:-:*:*:*:*:*:*:*"],"versions":[{"version":"11.2.0","lessThan":"11.2.4-h1","versionType":"custom","status":"affected"},{"version":"11.1.0","lessThan":"11.1.5-h1","versionType":"custom","status":"affected"},{"version":"11.0.0","lessThan":"11.0.6-h1","versionType":"custom","status":"affected"},{"version":"10.2.0","lessThan":"10.2.12-h2","versionType":"custom","status":"affected"},{"version":"10.1.0","lessThan":"10.1.14-h6","versionType":"custom","status":"affected"}]},{"vendor":"paloaltonetworks","product":"pan-os","defaultStatus":"unknown","cpes":["cpe:2.3:o:paloaltonetworks:pan-os:-:*:*:*:*:*:*:*"],"versions":[{"version":"11.2.0","lessThan":"11.2.4-h1","versionType":"custom","status":"affected"},{"version":"11.1.0","lessThan":"11.1.5-h1","versionType":"custom","status":"affected"},{"version":"11.0.0","lessThan":"11.0.6-h1","versionType":"custom","status":"affected"},{"version":"10.2.0","lessThan":"10.2.12-h2","versionType":"custom","status":"affected"},{"version":"10.1.0","lessThan":"10.1.14-h6","versionType":"custom","status":"affected"}]},{"vendor":"paloaltonetworks","product":"pan-os","defaultStatus":"unknown","cpes":["cpe:2.3:o:paloaltonetworks:pan-os:-:*:*:*:*:*:*:*"],"versions":[{"version":"11.2.0","lessThan":"11.2.4-h1","versionType":"custom","status":"affected"},{"version":"11.1.0","lessThan":"11.1.5-h1","versionType":"custom","status":"affected"},{"version":"11.0.0","lessThan":"11.0.6-h1","versionType":"custom","status":"affected"},{"version":"10.2.0","lessThan":"10.2.12-h2","versionType":"custom","status":"affected"},{"version":"10.1.0","lessThan":"10.1.14-h6","versionType":"custom","status":"affected"}]}]}],"metrics":{"cvssMetricV40":[{"source":"psirt@paloaltonetworks.com","type":"Secondary","cvssData":{"version":"4.0","vectorString":"CVSS:4.0/AV:N/AC:L/AT:N/PR:H/UI:N/VC:N/VI:H/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:N/R:U/V:C/RE:H/U:Red","baseScore":6.9,"baseSeverity":"MEDIUM","attackVector":"NETWORK","attackComplexity":"LOW","attackRequirements":"NONE","privilegesRequired":"HIGH","userInteraction":"NONE","vulnConfidentialityImpact":"NONE","vulnIntegrityImpact":"HIGH","vulnAvailabilityImpact":"NONE","subConfidentialityImpact":"NONE","subIntegrityImpact":"NONE","subAvailabilityImpact":"NONE","exploitMaturity":"NOT_DEFINED","confidentialityRequirement":"NOT_DEFINED","integrityRequirement":"NOT_DEFINED","availabilityRequirement":"NOT_DEFINED","modifiedAttackVector":"NOT_DEFINED","modifiedAttackComplexity":"NOT_DEFINED","modifiedAttackRequirements":"NOT_DEFINED","modifiedPrivilegesRequired":"NOT_DEFINED","modifiedUserInteraction":"NOT_DEFINED","modifiedVulnConfidentialityImpact":"NOT_DEFINED","modifiedVulnIntegrityImpact":"NOT_DEFINED","modifiedVulnAvailabilityImpact":"NOT_DEFINED","modifiedSubConfidentialityImpact":"NOT_DEFINED","modifiedSubIntegrityImpact":"NOT_DEFINED","modifiedSubAvailabilityImpact":"NOT_DEFINED","Safety":"NOT_DEFINED","Automatable":"NO","Recovery":"USER","valueDensity":"CONCENTRATED","vulnerabilityResponseEffort":"HIGH","providerUrgency":"RED"}}],"cvssMetricV31":[{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H","baseScore":7.2,"baseSeverity":"HIGH","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"HIGH","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"HIGH","integrityImpact":"HIGH","availabilityImpact":"HIGH"},"exploitabilityScore":1.2,"impactScore":5.9}],"ssvcV203":[{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","ssvcData":{"timestamp":"2024-11-18T00:00:00+00:00","id":"CVE-2024-9474","options":[{"exploitation":"active"},{"automatable":"no"},{"technicalImpact":"total"}],"role":"CISA Coordinator","version":"2.0.3"}}]},"cisaExploitAdd":"2024-11-18","cisaActionDue":"2024-12-09","cisaRequiredAction":"Apply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable. Additionally, the management interfaces for affected devices should not be exposed to untrusted networks, including the internet.","cisaVulnerabilityName":"Palo Alto Networks PAN-OS Management Interface OS Command Injection Vulnerability","weaknesses":[{"source":"psirt@paloaltonetworks.com","type":"Secondary","description":[{"lang":"en","value":"CWE-78"}]},{"source":"nvd@nist.gov","type":"Primary","description":[{"lang":"en","value":"CWE-78"}]}],"configurations":[{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:o:paloaltonetworks:pan-os:*:*:*:*:*:*:*:*","versionStartIncluding":"10.1.0","versionEndExcluding":"10.1.14","matchCriteriaId":"19D52DC1-4441-4C88-B209-9B86FCC2162F"},{"vulnerable":true,"criteria":"cpe:2.3:o:paloaltonetworks:pan-os:*:*:*:*:*:*:*:*","versionStartIncluding":"10.2.0","versionEndExcluding":"10.2.12","matchCriteriaId":"7D294CCB-C898-444E-BD41-D423B96F8E23"},{"vulnerable":true,"criteria":"cpe:2.3:o:paloaltonetworks:pan-os:*:*:*:*:*:*:*:*","versionStartIncluding":"11.0.0","versionEndExcluding":"11.0.6","matchCriteriaId":"47CBEECE-EA41-4A58-8AE9-D695C76D4019"},{"vulnerable":true,"criteria":"cpe:2.3:o:paloaltonetworks:pan-os:*:*:*:*:*:*:*:*","versionStartIncluding":"11.1.0","versionEndExcluding":"11.1.5","matchCriteriaId":"413284AC-F55E-4037-90D4-D63A5FFC20C3"},{"vulnerable":true,"criteria":"cpe:2.3:o:paloaltonetworks:pan-os:*:*:*:*:*:*:*:*","versionStartIncluding":"11.2.0","versionEndExcluding":"11.2.4","matchCriteriaId":"7E4D3A51-0A40-4B19-AAFC-A2484B1CF5D7"},{"vulnerable":true,"criteria":"cpe:2.3:o:paloaltonetworks:pan-os:10.1.14:-:*:*:*:*:*:*","matchCriteriaId":"B41A7115-A370-49E1-B162-24803E6DD2CB"},{"vulnerable":true,"criteria":"cpe:2.3:o:paloaltonetworks:pan-os:10.1.14:h2:*:*:*:*:*:*","matchCriteriaId":"65949A49-03A7-491C-B327-127F050AC4F6"},{"vulnerable":true,"criteria":"cpe:2.3:o:paloaltonetworks:pan-os:10.1.14:h4:*:*:*:*:*:*","matchCriteriaId":"E8ACB147-B4C1-4964-B538-EAA117CC6DC1"},{"vulnerable":true,"criteria":"cpe:2.3:o:paloaltonetworks:pan-os:10.2.12:-:*:*:*:*:*:*","matchCriteriaId":"3D33A0FB-7538-42BF-84E8-7CCD7EEF9355"},{"vulnerable":true,"criteria":"cpe:2.3:o:paloaltonetworks:pan-os:10.2.12:h1:*:*:*:*:*:*","matchCriteriaId":"FB95D77F-1263-4D47-A0BB-94A6DA937115"},{"vulnerable":true,"criteria":"cpe:2.3:o:paloaltonetworks:pan-os:11.0.6:-:*:*:*:*:*:*","matchCriteriaId":"2B6C3AFF-3649-484C-A2FB-B71EE02FF176"},{"vulnerable":true,"criteria":"cpe:2.3:o:paloaltonetworks:pan-os:11.1.5:-:*:*:*:*:*:*","matchCriteriaId":"7B2C0E11-A6CE-419D-86A0-3930DE25B544"},{"vulnerable":true,"criteria":"cpe:2.3:o:paloaltonetworks:pan-os:11.2.4:-:*:*:*:*:*:*","matchCriteriaId":"C01AD190-F3C2-4349-A063-8C5C78B725B9"}]}]}],"references":[{"url":"https://security.paloaltonetworks.com/CVE-2024-9474","source":"psirt@paloaltonetworks.com","tags":["Vendor Advisory"]},{"url":"https://unit42.paloaltonetworks.com/cve-2024-0012-cve-2024-9474/","source":"af854a3a-2127-422b-91ae-364da2661108","tags":["Press/Media Coverage","Vendor Advisory"]},{"url":"https://github.com/k4nfr3/CVE-2024-9474","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","tags":["Exploit"]},{"url":"https://labs.watchtowr.com/pots-and-pans-aka-an-sslvpn-palo-alto-pan-os-cve-2024-0012-and-cve-2024-9474/","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","tags":["Exploit","Third Party Advisory"]},{"url":"https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2024-9474","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","tags":["US Government Resource"]}]}}]}