CVE-2024-9474
KEV ransomware PoC ×2large1Root Privilege Escalation via Command Injection in Palo Alto Networks PAN-OS
CISA: Palo Alto Networks PAN-OS Management Interface OS Command Injection Vulnerability
CVE-2024-9474 is an OS command injection flaw (CWE-78) in the Palo Alto Networks PAN-OS management web interface that allows a PAN-OS administrator to perform actions on the firewall with root privileges. It is triggered by an authenticated administrator through the management interface, and it becomes far more serious when chained with the separately disclosed CVE-2024-0012 management-interface authentication bypass, which hands unauthenticated attackers initial access before they escalate to root. A successful attacker gains root-level control of the device, enough to alter configurations, harvest credentials, and pivot into connected networks. Only PAN-OS deployments are affected — Palo Alto Networks states Cloud NGFW and Prisma Access are not impacted. Exploitation is confirmed in the wild: the flaw was added to CISA's KEV on 2024-11-18 with known ransomware use, reporting describes over 2,000 PAN-OS devices compromised in an ongoing campaign, and public PoC/exploit code is available.
What to do: Upgrade affected PAN-OS systems to the patched releases identified in the Palo Alto Networks security advisory, and also remediate CVE-2024-0012, which attackers are chaining with this flaw. Until patched, ensure the management interface is not exposed to untrusted networks including the internet, per CISA's required action. Because successful attackers obtain root access, review management and configuration audit logs for unexpected activity and rotate management credentials on any device showing signs of compromise.
| Palo Alto Networks PAN-OS | — |
Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.
A privilege escalation vulnerability in Palo Alto Networks PAN-OS software allows a PAN-OS administrator with access to the management web interface to perform actions on the firewall with root privileges. Cloud NGFW and Prisma Access are not impacted by this vulnerability.
- Affected
- Palo Alto Networks PAN-OS
- Required action
- Apply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable. Additionally, the management interfaces for affected devices should not be exposed to untrusted networks, including the internet.
- Due date
- Ransomware use
- Known
- Vendors
- paloaltonetworks
- Products
- pan-os
- Weakness
- CWE-78
- Vector
- CVSS:4.0/AV:N/AC:L/AT:N/PR:H/UI:N/VC:N/VI:H/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:N/R:U/V:C/RE:H/U:Red