# CVE-2024-9474

## Summary

- **CVE ID:** CVE-2024-9474
- **Severity:** MEDIUM
- **CVSS Score:** 6.9 (CVSS:4.0/AV:N/AC:L/AT:P/PR:H/UI:N/VC:N/VI:H/VA:N/SC:N/SI:N/SA:N/AU:N/R:U/V:C/RE:H/U:Red)
- **CWE:** CWE-78
- **Published:** Nov 18, 2024
- **Last Modified:** Aug 4, 2026

## Description

A privilege escalation vulnerability in Palo Alto Networks PAN-OS software allows a PAN-OS administrator with access to the management web interface to perform actions on the firewall with root privileges.

Cloud NGFW and Prisma Access are not impacted by this vulnerability.

## Affected Products

- Palo Alto Networks — Cloud NGFW (All)
- Palo Alto Networks — PAN-OS (11.2.0)
- Palo Alto Networks — PAN-OS (11.1.0)
- Palo Alto Networks — PAN-OS (11.0.0)
- Palo Alto Networks — PAN-OS (10.2.0)
- Palo Alto Networks — PAN-OS (10.1.0)
- Palo Alto Networks — Prisma Access (All)

## References

- [CNA](https://security.paloaltonetworks.com/CVE-2024-9474)
- [CISA-ADP](https://labs.watchtowr.com/pots-and-pans-aka-an-sslvpn-palo-alto-pan-os-cve-2024-0012-and-cve-2024-9474/)
- [CISA-ADP](https://github.com/k4nfr3/CVE-2024-9474)
- [CISA-ADP](https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2024-9474)
- [CVE](https://unit42.paloaltonetworks.com/cve-2024-0012-cve-2024-9474/)

## Exploitation Prediction (EPSS)

- **EPSS Score:** 94.70%
- **EPSS Percentile:** 99.9

## Known Exploited Vulnerabilities (KEV)

- **Date Added:** Nov 18, 2024
- **Due Date:** Dec 9, 2024

---
_Exported from OnDuty AI Vulnerability Intelligence on 2026-09-10._