Skip to content
COOEY

EXPOSURES › CVE-2024-9474

CVE-2024-9474

CRITICAL ⌖ ON CISA KEV · EXPLOITED
DETAIL
SourceCISA-KEV · kev Published2024-11-18 Referencehttps://nvd.nist.gov/vuln/detail/CVE-2024-9474 ↗
⚡ RCE ⌖ EXPLOITED IN THE WILD SHAME 85/100 ransomwarerceexploited-in-wildunpatched

Palo Alto Networks PAN-OS management interface suffered an OS command injection vulnerability allowing privilege escalation.

An OS command injection flaw in the PAN-OS management interface allowed attackers to escalate privileges via the web-based management interface on firewalls and VPN concentrators. This is critical for DIB organizations relying on Palo Alto firewalls, as it directly enables remote code execution and aligns with CISA's KEV list, indicating active exploitation. Organizations must immediately patch PAN-OS and restrict management interface access to mitigate this high-embarrassment failure.

Shame score — A critical OS command injection flaw in a widely deployed firewall OS was actively exploited in the wild and linked to ransomware, demonstrating severe negligence and avoidability.

▸ RECOMMENDED ACTION  Actively exploited (CISA KEV) — remediate now, ahead of your normal patch cycle.

DESCRIPTION

Palo Alto Networks PAN-OS contains an OS command injection vulnerability that allows for privilege escalation through the web-based management interface for several PAN products, including firewalls and VPN concentrators.

AFFECTED FEDRAMP PRODUCTS · 2
PRODUCTSTATUS
GCS-HIGH
Palo Alto Networks, Inc.
Ready
Palo Alto Networks Government Cloud Services
Palo Alto Networks, Inc.
Authorized