CVE-2024-9474

Source
https://cve.org/CVERecord?id=CVE-2024-9474
Import Source
https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2024-9474.json
JSON Data
https://api.osv.dev/v1/vulns/CVE-2024-9474
Published
2024-11-18T16:15:29.780Z
Modified
2026-03-15T13:45:09.512499Z
Severity
  • 7.2 (High) CVSS_V3 - CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H CVSS Calculator
Summary
[none]
Details

A privilege escalation vulnerability in Palo Alto Networks PAN-OS software allows a PAN-OS administrator with access to the management web interface to perform actions on the firewall with root privileges.

Cloud NGFW and Prisma Access are not impacted by this vulnerability.

References

Affected packages

Git /

Affected ranges

Database specific

unresolved_ranges
[
    {
        "events": [
            {
                "introduced": "10.1.0"
            },
            {
                "fixed": "10.1.14"
            }
        ]
    },
    {
        "events": [
            {
                "introduced": "10.2.0"
            },
            {
                "fixed": "10.2.12"
            }
        ]
    },
    {
        "events": [
            {
                "introduced": "11.0.0"
            },
            {
                "fixed": "11.0.6"
            }
        ]
    },
    {
        "events": [
            {
                "introduced": "11.1.0"
            },
            {
                "fixed": "11.1.5"
            }
        ]
    },
    {
        "events": [
            {
                "introduced": "11.2.0"
            },
            {
                "fixed": "11.2.4"
            }
        ]
    },
    {
        "events": [
            {
                "introduced": "0"
            },
            {
                "last_affected": "10.1.14-NA"
            }
        ]
    },
    {
        "events": [
            {
                "introduced": "0"
            },
            {
                "last_affected": "10.1.14-h2"
            }
        ]
    },
    {
        "events": [
            {
                "introduced": "0"
            },
            {
                "last_affected": "10.1.14-h4"
            }
        ]
    },
    {
        "events": [
            {
                "introduced": "0"
            },
            {
                "last_affected": "10.2.12-NA"
            }
        ]
    },
    {
        "events": [
            {
                "introduced": "0"
            },
            {
                "last_affected": "10.2.12-h1"
            }
        ]
    },
    {
        "events": [
            {
                "introduced": "0"
            },
            {
                "last_affected": "11.0.6-NA"
            }
        ]
    },
    {
        "events": [
            {
                "introduced": "0"
            },
            {
                "last_affected": "11.1.5-NA"
            }
        ]
    },
    {
        "events": [
            {
                "introduced": "0"
            },
            {
                "last_affected": "11.2.4-NA"
            }
        ]
    }
]
source
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2024-9474.json"