PAN-OS: Privilege Escalation (PE) Vulnerability in the Web Management Interface
- Sévérité
- Élevée7,2CVSS 3.1, Élevée
- EPSS
- 95 %
- Publiée
- 18 nov. 2024
- Mise à jour
- 4 août 2026
Description
Le titre, la description et les consignes de l’éditeur sont cités depuis les enregistrements sources (en anglais).
A privilege escalation vulnerability in Palo Alto Networks PAN-OS software allows a PAN-OS administrator with access to the management web interface to perform actions on the firewall with root privileges. Cloud NGFW and Prisma Access are not impacted by this vulnerability.
Faiblesse : CWE-78
Exploitée activement
Ajoutée au catalogue CISA KEV le 18 nov. 2024
Date limite de remédiation fédérale : 9 déc. 2024
Utilisation connue par des rançongiciels
Action requise : Apply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable. Additionally, the management interfaces for affected devices should not be exposed to untrusted networks, including the internet.
Prédiction d’exploitation
Probabilité d’exploitation de 95 % dans les 30 prochains jours (percentile 100 %).
CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H
Ce qu’indique la source, par branche
Versions comparées par Patcharo
Palo Alto Networks PAN-OSSource : Palo Alto Networks (CVE record)
| Branche | Affectées | Corrigé en |
|---|---|---|
| 11.2 | >= 11.2.0, < 11.2.4-h1 | 11.2.4-h1 |
| 11.1 | >= 11.1.0, < 11.1.5-h1 | 11.1.5-h1 |
| 11.0 | >= 11.0.0, < 11.0.6-h1 | 11.0.6-h1 |
| 10.2 | >= 10.2.0, < 10.2.12-h2 | 10.2.12-h2 |
| 10.1 | >= 10.1.0, < 10.1.14-h6 | 10.1.14-h6 |
Selon l’éditeur, les versions non listées ne sont pas affectées.
Contournement / Remédiation de l’éditeur
Contournement · PAN-OS
Recommended mitigation—The vast majority of firewalls already follow Palo Alto Networks and industry best practices. However, if you haven’t already, we strongly recommend that you secure access to your management interface according to our best practice deployment guidelines. Specifically, you should restrict access to the management interface to only trusted internal IP addresses to prevent external access from the internet. Review information about how to secure management access to your Palo Alto Networks firewalls: * Palo Alto Networks LIVEcommunity article: https://docs.paloaltonetworks.com/best-practices/10-1/administrative-access-best-practices/administrative-access-best-practices/deploy-administrative-access-best-practices
Remédiation de l’éditeur · PAN-OS
This issue is fixed in PAN-OS 10.1.14-h6, PAN-OS 10.2.12-h2, PAN-OS 11.0.6-h1, PAN-OS 11.1.5-h1, PAN-OS 11.2.4-h1, and all later PAN-OS versions. In addition, in an attempt to provide the most seamless upgrade path for our customers, we are making fixes available for other TAC-preferred and commonly deployed maintenance releases. * Additional PAN-OS 11.2 fixes: * 11.2.0-h1 * 11.2.1-h1 * 11.2.2-h2 * 11.2.3-h3 * 11.2.4-h1 * Additional PAN-OS 11.1 fixes: * 11.1.0-h4 * 11.1.1-h2 * 11.1.2-h15 * 11.1.3-h11 * 11.1.4-h7 * 11.1.5-h1 * Additional PAN-OS 11.0 fixes: * 11.0.0-h4 * 11.0.1-h5 * 11.0.2-h5 * 11.0.3-h13 * 11.0.4-h6 * 11.0.5-h2 * 11.0.6-h1 * Additional PAN-OS 10.2 fixes: * 10.2.0-h4 * 10.2.1-h3 * 10.2.2-h6 * 10.2.3-h14 * 10.2.4-h32 * 10.2.5-h9 * 10.2.6-h6 * 10.2.7-h18 * 10.2.8-h15 * 10.2.9-h16 * 10.2.10-h9 * 10.2.11-h6 * 10.2.12-h2 * Additional PAN-OS 10.1 fixes: * 10.1.9-h14 * 10.1.10…
Références
- https://security.paloaltonetworks.com/CVE-2024-9474(s’ouvre dans un nouvel onglet)
- https://unit42.paloaltonetworks.com/cve-2024-0012-cve-2024-9474/(s’ouvre dans un nouvel onglet)
- https://github.com/k4nfr3/CVE-2024-9474(s’ouvre dans un nouvel onglet)
- https://labs.watchtowr.com/pots-and-pans-aka-an-sslvpn-palo-alto-pan-os-cve-2024-0012-and-cve-2024-9474/(s’ouvre dans un nouvel onglet)
- https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2024-9474(s’ouvre dans un nouvel onglet)
Provenance
Chaque information de cette page provient des sources ci-dessous. Rien n’est rédigé par une IA.
- Palo Alto Networks (CVE record)
- Palo Alto Networks (CVE record) · 27 sept. 2026, 23:46 UTC · Analyseur patcharo-cve5/1.1.0
- CISA Known Exploited Vulnerabilities
- CISA Known Exploited Vulnerabilities · 27 sept. 2026, 23:42 UTC · Analyseur patcharo-kev/1.0.0
- NVD
- NVD · 27 sept. 2026, 23:44 UTC · Analyseur patcharo-nvd/1.0.0
- FIRST EPSS
- FIRST EPSS · 27 sept. 2026, 23:46 UTC · Analyseur patcharo-epss/1.0.0
Dernière vérification : 28 sept. 2026, 02:31 UTC