PoC Index

CVE-2024-9474

KEV RANSOMWAREHIGH 7.2EPSS 94.7%

A privilege escalation vulnerability in Palo Alto Networks PAN-OS software allows a PAN-OS administrator with access to the management web interface to perform actions on the firewall with root privileges.Cloud NGFW and Prisma Access are not impacted by this vulnerability.

CVSS v4.0
6.9 MEDIUMCVSS:4.0/AV:N/AC:L/AT:N/PR:H/UI:N/VC:N/VI:H/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:N/R:U/V:C/RE:H/U:Red
CVSS v3.1
7.2 HIGHCVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H
EPSS
94.70% chance of exploitation in the next 30 days, 100th percentile
CISA KEV
added 2024-11-18, used in ransomware campaigns
Nuclei
high · CWE-78
Published
2024-11-18
Updated
2026-08-04

Proof-of-concept exploits (11)

Nuclei templates (1)

Metasploit modules (1)

References

Related