S4E just found a high-severity finding from top 10 tcp port service scan
PlatformPlansPartners
Resources
ToolsBlogDocs
Sign Up →
high·Product Based Web Vulnerabilities·Updated Nov 20, 2024

CVE-2024-9474 Scanner

CVE-2024-9474 Scanner - Command Injection vulnerability in PAN-OS Management Web Interface

Est. Time~10 seconds
Scan TypeSingle Scan
Targetsdomain, ipv4, subdomain
CostFree
2.4k
Times Used
continuous scan runs
4.2k
Continuously Checked
assets under CS
0
Vulnerabilities Found
confirmed findings
References
🔴
CISA Known Exploited Vulnerability
This CVE is actively exploited in the wild. CISA mandates federal agencies to patch immediately.
6.9
CVSSmedium
Exploitable remotely over the internet · requires high privileges.
Description

A privilege escalation vulnerability in Palo Alto Networks PAN-OS software allows a PAN-OS administrator with access to the management web interface to perform actions on the firewall with root privileges. Cloud NGFW and Prisma Access are not impacted by this vulnerability.

Attack Vector
Network
Privileges Req.
High
User Interaction
None
Affected
Cloud NGFWby Palo Alto Networks
All
PAN-OSby Palo Alto Networks
AFFECTED< 11.2.4-h1→SAFE ✓≥ 11.2.4-h1
Prisma Accessby Palo Alto Networks
All
pan-osby paloaltonetworks
AFFECTED< 11.2.4-h1→SAFE ✓≥ 11.2.4-h1
Updated Sep 28, 2026View on NVD →
Detail

PAN-OS is a leading operating system powering Palo Alto Networks' next-generation firewalls. It is widely utilized by enterprises and governments to secure their networks from cyber threats. The Management Web Interface of PAN-OS allows administrators to manage firewall configurations and monitor traffic. Typically used by IT security teams, it serves critical functions in protecting sensitive data and maintaining compliance. With its advanced capabilities, PAN-OS is a cornerstone of enterprise network security worldwide.

The Command Injection vulnerability in PAN-OS Management Web Interface allows malicious users to execute arbitrary commands. Exploiting this vulnerability can escalate privileges, enabling attackers to gain root-level access. This could lead to complete control over the firewall, bypassing security measures. The vulnerability poses significant risks, especially in environments handling sensitive or classified information.
The vulnerability exists due to improper handling of user inputs in certain API endpoints. Specifically, the /php/utils/createRemoteAppwebSession.php endpoint fails to sanitize inputs adequately, allowing for injection of unauthorized commands. The parameter user can be exploited with crafted payloads to execute system-level commands. The vulnerability relies on the X-PAN-AUTHCHECK header, which bypasses some authentication checks. Exploitation can result in arbitrary command execution on the affected device with root privileges.
Possible Effects:

  • Complete compromise of the firewall and associated network.
  • Unauthorized access to sensitive network traffic and configurations.
  • Potential for lateral movement to other systems in the network.
  • Loss of control over security operations, leading to data theft or destruction.

S4E offers unparalleled insights into your digital exposure. With tools like the CVE-2024-9474 scanner, you can identify and mitigate critical vulnerabilities before attackers exploit them. Our platform empowers you with real-time alerts, detailed reports, and tailored remediation steps. Join S4E to secure your assets and ensure peace of mind. Sign up today and take control of your cybersecurity landscape!

Solution Advice
  • Immediately apply any security patches released by Palo Alto Networks for PAN-OS.
  • Restrict access to the Management Web Interface to trusted IP addresses.
  • Monitor logs for unusual activities, especially related to X-PAN-AUTHCHECK headers.
  • Regularly audit and update firewall configurations to minimize exposure.
  • Educate administrators about secure management practices and potential risks.

Get AI-powered remediation steps tailored to your asset.

Try AI Solutions →

Check your infrastructure.
Right now.

11,000+ scanners. Free to start. No credit card required.