High severity7.2CISA KEVNVD Advisory· Published Nov 18, 2024· Updated Aug 4, 2026
CVE-2024-9474
CVE-2024-9474
Description
A privilege escalation vulnerability in Palo Alto Networks PAN-OS software allows a PAN-OS administrator with access to the management web interface to perform actions on the firewall with root privileges.
Cloud NGFW and Prisma Access are not impacted by this vulnerability.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected products
13cpe:2.3:o:paloaltonetworks:pan-os:*:*:*:*:*:*:*:*+ 10 more
- cpe:2.3:o:paloaltonetworks:pan-os:*:*:*:*:*:*:*:*range: >=10.1.0,<10.1.14
- cpe:2.3:o:paloaltonetworks:pan-os:10.1.14:-:*:*:*:*:*:*
- cpe:2.3:o:paloaltonetworks:pan-os:10.1.14:h2:*:*:*:*:*:*
- cpe:2.3:o:paloaltonetworks:pan-os:10.1.14:h4:*:*:*:*:*:*
- cpe:2.3:o:paloaltonetworks:pan-os:10.2.12:-:*:*:*:*:*:*
- cpe:2.3:o:paloaltonetworks:pan-os:10.2.12:h1:*:*:*:*:*:*
- cpe:2.3:o:paloaltonetworks:pan-os:11.0.6:-:*:*:*:*:*:*
- cpe:2.3:o:paloaltonetworks:pan-os:11.1.5:-:*:*:*:*:*:*
- cpe:2.3:o:paloaltonetworks:pan-os:11.2.4:-:*:*:*:*:*:*
- (no CPE)
- (no CPE)range: 11.2.0
- Range: All
- Range: All
Patches
Vulnerability mechanics
References
4- labs.watchtowr.com/pots-and-pans-aka-an-sslvpn-palo-alto-pan-os-cve-2024-0012-and-cve-2024-9474/nvdExploitThird Party Advisory
- security.paloaltonetworks.com/CVE-2024-9474nvdVendor Advisory
- unit42.paloaltonetworks.com/cve-2024-0012-cve-2024-9474/nvdPress/Media CoverageVendor Advisory
- www.cisa.gov/known-exploited-vulnerabilities-catalognvdUS Government Resource
News mentions
2- The Patch Gap: Why Defenders Need to Think in Chains, Not ChecklistsDark Reading · Aug 10, 2026
- Risky Business #771 -- Palo Alto's firewall 0days are very, very stupidRisky Business · Nov 20, 2024