PAN-OS management web interface

CVE-2024-9474: Admin-to-root command injection, the second half of the 2024 firewall chain

A PAN-OS administrator can run commands as root through the management interface. Alone it needs admin rights; chained with CVE-2024-0012 or CVE-2025-0108, it gave attackers root on exposed firewalls.

Published Updated

ExploitedYes, in CISA KEVAdded 18 Nov 2024
Ransomware useKnownPer CISA
SeverityMEDIUMCVSS 4.0 6.9
EPSS95%Chance of exploitation in 30 days
Public exploitYes
FixAvailable

Affected and fixed versions

Product / branchFixed in
PAN-OS 11.211.2.0-h1, 11.2.1-h1, 11.2.2-h2, 11.2.3-h3, 11.2.4-h1 or later
PAN-OS 11.111.1.0-h4, 11.1.1-h2, 11.1.2-h15, 11.1.3-h11, 11.1.4-h7, 11.1.5-h1 or later
PAN-OS 11.011.0.0-h4, 11.0.1-h5, 11.0.2-h5, 11.0.3-h13, 11.0.4-h6, 11.0.5-h2, 11.0.6-h1 or later (branch now end of life)
PAN-OS 10.210.2.0-h4, 10.2.1-h3, 10.2.2-h6, 10.2.3-h14, 10.2.4-h32, 10.2.5-h9, 10.2.6-h6, 10.2.7-h18, 10.2.8-h15, 10.2.9-h16, 10.2.10-h9, 10.2.11-h6, 10.2.12-h2 or later
PAN-OS 10.110.1.3-h4, 10.1.6-h9, 10.1.8-h8, 10.1.9-h14, 10.1.10-h9, 10.1.11-h10, 10.1.12-h3, 10.1.13-h5, 10.1.14-h6 or later
Cloud NGFW, Prisma AccessNot affected

Always confirm against the vendor advisory, which lists every fixed hotfix.

What it is

The management web interface writes some user-supplied values, including the username of a new session, into an audit log by building a shell command. On vulnerable versions those values weren’t sanitized, so shell metacharacters in a crafted username ran as commands, with root privileges.

On its own the bug needs a logged-in PAN-OS administrator, which is why Palo Alto rated it medium (CVSS 6.9). In practice attackers never needed real credentials. They paired it with a login bypass:

  • November 2024: CVE-2024-0012, which turned a single header into admin access.
  • February 2025: CVE-2025-0108, a newer bypass found in the same code.

Either pair gives unauthenticated root on the firewall. That’s why the KEV catalog lists this “medium” bug as exploited.

Am I affected?

The bug is reachable by anyone who can log in to, or bypass the login of, the management web interface on an affected version. This range is wider than CVE-2024-0012’s: it includes PAN-OS 10.1 and WildFire appliances as well as firewalls and Panorama.

The real risk is the same as for the bypasses: a management interface reachable from the internet or another untrusted network, either directly or through a management profile on a dataplane interface (often port 4443 on a GlobalProtect address).

What to do

1. Upgrade to a fixed hotfix. If you’re still on PAN-OS 10.1 or 11.0, both now end of life, move to a supported branch.

2. Restrict management access to trusted internal addresses only. This also reduces the risk from malicious or compromised administrator accounts, which can exploit the bug without any bypass.

3. Review who has admin rights, especially local accounts and API keys. Any of them is a path to root on an unpatched device.

If a firewall was compromised

Attackers with root on a firewall can install web shells, implants or miners and read everything stored on it. Don’t try to clean it in place:

  1. Contact Palo Alto Networks support. They can review a tech support file for known indicators and guide a rebuild of the device.
  2. Rebuild and restore carefully. Restore from a configuration backup taken before the compromise. If you only have a later backup, review it for administrators, objects and rules you didn’t add.
  3. Rotate everything the firewall knew:
    • local administrator passwords and API keys
    • LDAP, RADIUS and User-ID service account passwords
    • IPsec pre-shared keys
    • certificates and private keys on the device, including GlobalProtect, SSL decryption and management certificates
  4. Look beyond the firewall. Check for logins and lateral movement from the firewall’s addresses into your network during the exposure window.

For detection guidance and indicators of compromise from these campaigns, see CVE-2024-0012.

Sources

Page changelog

  • Full analysis published.

KEV status, EPSS score and vendor data refreshed automatically, last on 10 Oct 2026.

Get alerts

A notification when we publish a new analysis or a covered vendor gets a new actively exploited CVE. No account, no email.