← Vulnerability feed

Vulnerability record · CVE-2024-9474 · published 18 November 2024

CVE-2024-9474: PAN-OS Management Interface OS Command Injection Privilege Escalation

Paloaltonetworks · Pan Os

PAN-OS contains an OS command injection flaw (CWE-78) in the management web interface that lets an authenticated administrator execute actions on the firewall with root privileges. It matters because a lower-privileged management user can gain full root control of the device, and the flaw is being exploited in the wild.

6.9 CVSS 4.0 Medium CISA KEV since 18 Nov 2024 Known ransomware use EPSS 95% · top 0.1% CWE-78 · OS command injection
6.9CVSS 4.0 base score
95%EPSS exploitation probability, 30 days
YesIn CISA KEV, fix deadline passed
1Affected product versions listed by NVD
5References, 2 tagged exploit
4 Aug 2026Last modified by NVD

Description

A privilege escalation vulnerability in Palo Alto Networks PAN-OS software allows a PAN-OS administrator with access to the management web interface to perform actions on the firewall with root privileges. Cloud NGFW and Prisma Access are not impacted by this vulnerability.

CVSS:4.0/AV:N/AC:L/AT:N/PR:H/UI:N/VC:N/VI:H/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:N/R:

Automated analysis

Generated by VULONE's analysis model from the NVD record, CISA KEV and EPSS data on 16 September 2026. Confidence: high.

critical priorityIt is in CISA KEV with known ransomware use, has a very high EPSS score, and allows root-level compromise of a perimeter security device.

What it is

PAN-OS contains an OS command injection flaw (CWE-78) in the management web interface that lets an authenticated administrator execute actions on the firewall with root privileges. It matters because a lower-privileged management user can gain full root control of the device, and the flaw is being exploited in the wild.

Impact

An attacker with administrator access to the management web interface gains root-level execution on the firewall, enabling full control of the device and its configuration. This can lead to data theft, configuration tampering, or use of the firewall as a foothold in the network.

Attack surface

Reached over the network via the PAN-OS management web interface (CVSS 4.0 AV:N). It requires high privileges (PR:H) and no user interaction (UI:N), so an attacker must already hold a valid administrator account on the management interface.

Exploitation

Listed in CISA KEV (added 2024-11-18, due 2024-12-09) with known ransomware campaign use, and EPSS 30-day probability is 0.94701 (99.85th percentile). Public exploit references exist, including a GitHub PoC and third-party analysis, indicating active exploitation.

What to do

  • Apply the vendor patch for PAN-OS per the Palo Alto Networks advisory as the first action.
  • Restrict management web interface access to trusted internal networks only; never expose it to the internet.
  • Enforce least privilege on PAN-OS administrator accounts and audit existing admin users.
  • Monitor and restrict access to the management interface using firewall rules or jump hosts.
  • If patching is not immediately possible, follow CISA KEV required actions or discontinue use of the affected product.

Detection

  • Monitor PAN-OS management interface logs for unexpected command execution or anomalous admin activity.
  • Alert on new or unusual administrator accounts and privilege changes on the firewall.
  • Hunt for outbound connections or process activity on the firewall consistent with post-exploitation root access.
  • Review authentication logs for management interface access from untrusted or unexpected source IPs.

This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.

Exploitation in the wild

CISA added CVE-2024-9474 to the Known Exploited Vulnerabilities catalog on 18 November 2024 as "Palo Alto Networks PAN-OS Management Interface OS Command Injection Vulnerability". CISA reports known use in ransomware campaigns. Required action: Apply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable. Additionally, the management interfaces for affected devices should not be exposed to untrusted networks, including the internet. Federal deadline 9 December 2024.

Affected products

1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

Track CVE-2024-9474 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

10.0CVE-2024-3400PAN-OS GlobalProtect command injection allows unauthenticated root code executionA command injection caused by arbitrary file creation in the GlobalProtect feature of Palo Alto Networks PAN-OS lets an unauthenticated attacker run …KEVEPSS 100%analysed10.0CVE-2020-2021PAN-OS SAML signature verification bypass allows authentication bypassPAN-OS fails to properly verify SAML signatures when SAML authentication is enabled and the 'Validate Identity Provider Certificate' option is unchec…KEVEPSS 4.4%analysed9.8CVE-2017-15944PAN-OS management interface input validation flaw allows remote code executionPAN-OS versions before 6.1.19, 7.0.x before 7.0.19, 7.1.x before 7.1.14, and 8.0.x before 8.0.6 contain an input validation and memory buffer overflo…KEVEPSS 98%analysed9.3CVE-2026-0300PAN-OS User-ID Authentication Portal buffer overflow allows root code executionA buffer overflow (out-of-bounds write, CWE-787) in the User-ID Authentication Portal (Captive Portal) service of Palo Alto Networks PAN-OS lets an u…KEVEPSS 32%analysed9.3CVE-2024-0012PAN-OS Management Web Interface Authentication BypassPAN-OS contains a missing authentication flaw (CWE-306) in the management web interface that lets an unauthenticated network attacker obtain PAN-OS a…KEVEPSS 100%analysed8.8CVE-2025-0108PAN-OS management web interface authentication bypassPAN-OS contains a missing-authentication flaw (CWE-306) in the management web interface that lets an unauthenticated attacker with network access inv…KEVEPSS 98%analysed8.7CVE-2024-3393PAN-OS DNS Security packet causes firewall reboot and maintenance modeA denial of service flaw in the DNS Security feature of Palo Alto Networks PAN-OS lets an unauthenticated attacker send a crafted packet through the …KEVEPSS 28%analysed8.6CVE-2022-0028PAN-OS URL filtering misconfiguration enables reflected TCP DoSA PAN-OS URL filtering policy misconfiguration allows a network-based attacker to use PA-Series, VM-Series and CN-Series firewalls to conduct reflect…KEVEPSS 2.4%analysed

Source: NIST National Vulnerability Database (record CVE-2024-9474), CISA KEV, FIRST EPSS (scores of 2026-09-25). This page is refreshed as NVD updates the record.