Evidence dossier
CVE-2024-9474
PAN-OS: Privilege Escalation (PE) Vulnerability in the Web Management Interface
Exploited in the wild (CISA KEV since Nov 18, 2024). palo_alto reports CVSS 4.0 6.9. Severity assessments differ within at least one CVSS version. EPSS estimates 94.7% exploit likelihood as of Aug 26, 2026.
As of Aug 27, 2026
Normalized restatement
A privilege escalation vulnerability in Palo Alto Networks PAN-OS software allows a PAN-OS administrator with access to the management web interface to perform actions on the firewall with root privileges. Cloud NGFW and Prisma Access are not impacted by this vulnerability.
- State
- PUBLISHED
- Published
- Nov 18, 2024
- Updated
- Aug 4, 2026
- Evidence coverage
- 72%
Evidence chronology
What was known when
- Source dateFirst observed by CASCACISA KEVOriginal evidence ↗
Exploitation cataloged: Palo Alto Networks PAN-OS Management Interface OS Command Injection Vulnerability
Inspect raw assertion
- Field
observed_exploitation- Value
- Palo Alto Networks PAN-OS Management Interface OS Command Injection Vulnerability
- Source dateSource date omittedFirst observed by CASCACISA-ADPOriginal evidence ↗
Record text: CISA ADP Vulnrichment
Inspect raw assertion
- Field
container- Value
- CISA ADP Vulnrichment
- Source dateSource date omittedFirst observed by CASCACVE ProgramOriginal evidence ↗
Record text: CVE Program Container
Inspect raw assertion
- Field
container- Value
- CVE Program Container
- Source dateSource date omittedFirst observed by CASCApalo_altoOriginal evidence ↗
Record text: PAN-OS: Privilege Escalation (PE) Vulnerability in the Web Management Interface
Inspect raw assertion
- Field
container- Value
- PAN-OS: Privilege Escalation (PE) Vulnerability in the Web Management Interface
- Source dateFirst observed by CASCAFIRST EPSSOriginal evidence ↗
EPSS score: 94.69% probability · 99.85th percentile
Inspect raw assertion
- Field
model_probability- Value
- Probability 0.946870000000; percentile 0.998500000000
Assessments differ
Values are shown separately by source and CVSS version.
CISA KEV · catalog date Nov 18, 2024 · first observed Jul 19, 2026
FIRST EPSS · score date Aug 26, 2026 · 99.9th percentile · first observed Aug 26, 2026
palo_alto · CVSS 4.0 · first observed Aug 4, 2026 · values shown separately below
Evidence detail
Source limits and decisions
Why each evidence state has this value
casca-unknown-reasons-v1Eligible evidence is present for this bounded claim.
- Revision
- evidence-policy-v1.1.0
- Cutoff
- Aug 27, 2026
- Resolution
- None
Eligible evidence is present for this bounded claim.
- Revision
- evidence-policy-v1.1.0
- Cutoff
- Aug 27, 2026
- Resolution
- None
Eligible assertions materially conflict and remain visible side by side.
- Revision
- casca-direct-cvss-eligibility-v1
- Cutoff
- Aug 27, 2026
- Resolution
- Resolve conflict
The cited source assertion is retained while canonical product linkage remains open.
- Revision
- casca-factor-d-obligations-v1
- Cutoff
- Aug 27, 2026
- Resolution
- Resolve identity
Source comparison
Who said what
Palo Alto Networks PAN-OS Management Interface OS Command Injection Vulnerability
Inspect raw assertion
- Field
observed_exploitation- Value
- Palo Alto Networks PAN-OS Management Interface OS Command Injection Vulnerability
CISA ADP Vulnrichment
Inspect raw assertion
- Field
container- Value
- CISA ADP Vulnrichment
CVE Program Container
Inspect raw assertion
- Field
container- Value
- CVE Program Container
PAN-OS: Privilege Escalation (PE) Vulnerability in the Web Management Interface
Inspect raw assertion
- Field
container- Value
- PAN-OS: Privilege Escalation (PE) Vulnerability in the Web Management Interface
94.69% probability · 99.85th percentile
Inspect raw assertion
- Field
model_probability- Value
- Probability 0.946870000000; percentile 0.998500000000
Applicability
Cited product scope
Grouped from 1 configuration nodes in this exact snapshot. Visual grouping is navigational; asset exposure and root cause require cited evidence.
Identity source boundaries
- Cpe dictionary1,775,266 records · observed through 2026-07-21T06:45:29.809Z
27d65b0f-b718-4b4f-bb79-c47c68d09dfa - Cpe match643,502 records · observed through 2026-07-21T08:13:17.697Z
955dae73-7302-438b-aee1-058d7cc5d48e
9 scope groups
Canonical linkage remains open; the cited source assertion is retained below.
Inspect raw assertion
[{"status": "affected", "version": "11.2.0", "lessThan": "11.2.4-h1", "versionType": "custom"}, {"status": "affected", "version": "11.1.0", "lessThan": "11.1.5-h1", "versionType": "custom"}, {"status": "affected", "version": "11.0.0", "lessThan": "11.0.6-h1", "versionType": "custom"}, {"status": "affected", "version": "10.2.0", "lessThan": "10.2.12-h2", "versionType": "custom"}, {"status": "affected", "version": "10.1.0", "lessThan": "10.1.14-h6", "versionType": "custom"}]Canonical linkage remains open; the cited source assertion is retained below.
Inspect raw assertion
[{"status": "affected", "version": "11.2.0", "lessThan": "11.2.4-h1", "versionType": "custom"}, {"status": "affected", "version": "11.1.0", "lessThan": "11.1.5-h1", "versionType": "custom"}, {"status": "affected", "version": "11.0.0", "lessThan": "11.0.6-h1", "versionType": "custom"}, {"status": "affected", "version": "10.2.0", "lessThan": "10.2.12-h2", "versionType": "custom"}, {"status": "affected", "version": "10.1.0", "lessThan": "10.1.14-h6", "versionType": "custom"}]Canonical linkage remains open; the cited source assertion is retained below.
Inspect raw assertion
[{"status": "affected", "version": "11.2.0", "lessThan": "11.2.4-h1", "versionType": "custom"}, {"status": "affected", "version": "11.1.0", "lessThan": "11.1.5-h1", "versionType": "custom"}, {"status": "affected", "version": "11.0.0", "lessThan": "11.0.6-h1", "versionType": "custom"}, {"status": "affected", "version": "10.2.0", "lessThan": "10.2.12-h2", "versionType": "custom"}, {"status": "affected", "version": "10.1.0", "lessThan": "10.1.14-h6", "versionType": "custom"}]Canonical linkage remains open; the cited source assertion is retained below.
Inspect raw assertion
[{"status": "affected", "version": "11.2.0", "lessThan": "11.2.4-h1", "versionType": "custom"}, {"status": "affected", "version": "11.1.0", "lessThan": "11.1.5-h1", "versionType": "custom"}, {"status": "affected", "version": "11.0.0", "lessThan": "11.0.6-h1", "versionType": "custom"}, {"status": "affected", "version": "10.2.0", "lessThan": "10.2.12-h2", "versionType": "custom"}, {"status": "affected", "version": "10.1.0", "lessThan": "10.1.14-h6", "versionType": "custom"}]Canonical linkage remains open; the cited source assertion is retained below.
Inspect raw assertion
[{"status": "affected", "version": "11.2.0", "lessThan": "11.2.4-h1", "versionType": "custom"}, {"status": "affected", "version": "11.1.0", "lessThan": "11.1.5-h1", "versionType": "custom"}, {"status": "affected", "version": "11.0.0", "lessThan": "11.0.6-h1", "versionType": "custom"}, {"status": "affected", "version": "10.2.0", "lessThan": "10.2.12-h2", "versionType": "custom"}, {"status": "affected", "version": "10.1.0", "lessThan": "10.1.14-h6", "versionType": "custom"}]Canonical linkage remains open; the cited source assertion is retained below.
Inspect raw assertion
[{"status": "unaffected", "version": "All"}]Canonical linkage remains open; the cited source assertion is retained below.
Inspect raw assertion
[{"status": "affected", "version": "11.2.0", "lessThan": "11.2.4-h1", "versionType": "custom"}, {"status": "affected", "version": "11.1.0", "lessThan": "11.1.5-h1", "versionType": "custom"}, {"status": "affected", "version": "11.0.0", "lessThan": "11.0.6-h1", "versionType": "custom"}, {"status": "affected", "version": "10.2.0", "lessThan": "10.2.12-h2", "versionType": "custom"}, {"status": "affected", "version": "10.1.0", "lessThan": "10.1.14-h6", "versionType": "custom"}]Canonical linkage remains open; the cited source assertion is retained below.
Inspect raw assertion
[{"status": "unaffected", "version": "All"}]product-612afb736440531327cd224402d663e14e2a3f421cc65267d8acade0f3b99df7Linked exactInspect raw assertions
cpe:2.3:o:paloaltonetworks:pan-os:*:*:*:*:*:*:*:*- Official link
- Linked exact
- Role
- Vulnerable target
- Configuration
- 0 · node/0 · match 3
- Logic
- OR
- Version bounds
- from including 11.1.0; through excluding 11.1.5
- Match ID
413284ac-f55e-4037-90d4-d63a5ffc20c3
cpe:2.3:o:paloaltonetworks:pan-os:*:*:*:*:*:*:*:*- Official link
- Linked exact
- Role
- Vulnerable target
- Configuration
- 0 · node/0 · match 2
- Logic
- OR
- Version bounds
- from including 11.0.0; through excluding 11.0.6
- Match ID
47cbeece-ea41-4a58-8ae9-d695c76d4019
cpe:2.3:o:paloaltonetworks:pan-os:*:*:*:*:*:*:*:*- Official link
- Linked exact
- Role
- Vulnerable target
- Configuration
- 0 · node/0 · match 1
- Logic
- OR
- Version bounds
- from including 10.2.0; through excluding 10.2.12
- Match ID
7d294ccb-c898-444e-bd41-d423b96f8e23
cpe:2.3:o:paloaltonetworks:pan-os:10.2.12:h1:*:*:*:*:*:*- Official link
- Linked exact
- Role
- Vulnerable target
- Configuration
- 0 · node/0 · match 9
- Logic
- OR
- Version bounds
- No explicit bounds
- Match ID
fb95d77f-1263-4d47-a0bb-94a6da937115
cpe:2.3:o:paloaltonetworks:pan-os:11.2.4:-:*:*:*:*:*:*- Official link
- Linked exact
- Role
- Vulnerable target
- Configuration
- 0 · node/0 · match 12
- Logic
- OR
- Version bounds
- No explicit bounds
- Match ID
c01ad190-f3c2-4349-a063-8c5c78b725b9
cpe:2.3:o:paloaltonetworks:pan-os:*:*:*:*:*:*:*:*- Official link
- Linked exact
- Role
- Vulnerable target
- Configuration
- 0 · node/0 · match 4
- Logic
- OR
- Version bounds
- from including 11.2.0; through excluding 11.2.4
- Match ID
7e4d3a51-0a40-4b19-aafc-a2484b1cf5d7
cpe:2.3:o:paloaltonetworks:pan-os:10.2.12:-:*:*:*:*:*:*- Official link
- Linked exact
- Role
- Vulnerable target
- Configuration
- 0 · node/0 · match 8
- Logic
- OR
- Version bounds
- No explicit bounds
- Match ID
3d33a0fb-7538-42bf-84e8-7ccd7eef9355
cpe:2.3:o:paloaltonetworks:pan-os:10.1.14:h2:*:*:*:*:*:*- Official link
- Linked exact
- Role
- Vulnerable target
- Configuration
- 0 · node/0 · match 6
- Logic
- OR
- Version bounds
- No explicit bounds
- Match ID
65949a49-03a7-491c-b327-127f050ac4f6
cpe:2.3:o:paloaltonetworks:pan-os:10.1.14:h4:*:*:*:*:*:*- Official link
- Linked exact
- Role
- Vulnerable target
- Configuration
- 0 · node/0 · match 7
- Logic
- OR
- Version bounds
- No explicit bounds
- Match ID
e8acb147-b4c1-4964-b538-eaa117cc6dc1
cpe:2.3:o:paloaltonetworks:pan-os:11.0.6:-:*:*:*:*:*:*- Official link
- Linked exact
- Role
- Vulnerable target
- Configuration
- 0 · node/0 · match 10
- Logic
- OR
- Version bounds
- No explicit bounds
- Match ID
2b6c3aff-3649-484c-a2fb-b71ee02ff176
cpe:2.3:o:paloaltonetworks:pan-os:11.1.5:-:*:*:*:*:*:*- Official link
- Linked exact
- Role
- Vulnerable target
- Configuration
- 0 · node/0 · match 11
- Logic
- OR
- Version bounds
- No explicit bounds
- Match ID
7b2c0e11-a6ce-419d-86a0-3930de25b544
cpe:2.3:o:paloaltonetworks:pan-os:*:*:*:*:*:*:*:*- Official link
- Linked exact
- Role
- Vulnerable target
- Configuration
- 0 · node/0 · match 0
- Logic
- OR
- Version bounds
- from including 10.1.0; through excluding 10.1.14
- Match ID
19d52dc1-4441-4c88-b209-9b86fcc2162f
cpe:2.3:o:paloaltonetworks:pan-os:10.1.14:-:*:*:*:*:*:*- Official link
- Linked exact
- Role
- Vulnerable target
- Configuration
- 0 · node/0 · match 5
- Logic
- OR
- Version bounds
- No explicit bounds
- Match ID
b41a7115-a370-49e1-b162-24803e6dd2cb
Affected-product evidence
Accepted scope and product mapping
0 canonical links · 2 source-reported links
Canonical linkage remains open; the cited source assertion is retained below.
Vendor specified only by source · Product specified only by source
- Source class
- Direct cve affected
- Assertions
- 8
- Mapping revision
- cpe23-exact-mapping-v1
- Observed cutoff
- Aug 27, 2026
Retained assertion IDs
42144520-f3f8-40bf-a038-767f97fb418b70790570-1bb0-4f2e-aacb-48040617a6299dcd9dd5-7304-43b4-a219-d426397c00b9a9a9c187-d886-441d-a586-8e347c1b5849b0ba5ad2-f6bb-4332-b210-d3ef1808a810c784f691-e9db-415e-9a75-0e9f93f1b2cfd430ab6a-f770-4de8-bfac-a002533372fcf85ce07a-887e-4a51-a9e4-0873d80870ffCanonical linkage remains open; the cited source assertion is retained below.
Vendor specified only by source · Product specified only by source
- Source class
- Nvd cpe vulnerable target
- Assertions
- 13
- Mapping revision
- cpe23-exact-mapping-v1
- Observed cutoff
- Aug 27, 2026
Retained assertion IDs
0901826b-2cff-4d51-bbe4-0ce475c41346153b263d-b59f-4e9d-83a8-a1898fbfc20d37c60d83-389c-4d55-b07e-f3bb2167f1ae4712c28b-8ef6-4acb-8c9d-ff50df2eb2254ad61eab-e261-436d-bd88-8eeb3e1a64774bbb72c2-d042-4e06-a7b7-488e2a0ebd1b614b0b93-d8b4-47f4-bc1a-4b383852c13a9d9ce5a2-526c-49b4-be19-e207d53bab0eb4704777-ae51-4217-8c9b-e1077d4c39a6c635f1a9-602f-4fdb-b6cb-2ddd8161a77fc6bf042a-aee8-48c6-b571-734f7c771fe9e98d86ad-70df-4e3a-a940-cae7b31a514aef0b429d-a36d-407a-b95b-5fff118d5527Assessments
CVSS by origin
CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:HCVSS:4.0/AV:N/AC:L/AT:N/PR:H/UI:N/VC:N/VI:H/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:N/R:U/V:C/RE:H/U:RedCVSS:4.0/AV:N/AC:L/AT:N/PR:H/UI:N/VC:N/VI:H/VA:N/SC:N/SI:N/SA:N/AU:N/R:U/V:C/RE:H/U:RedCVSS:4.0/AV:N/AC:L/AT:P/PR:H/UI:N/VC:N/VI:H/VA:N/SC:N/SI:N/SA:N/AU:N/R:U/V:C/RE:H/U:RedDirect CVE/CNA normalized decisions
palo_alto
CVSS 4.0 · Primary · Original assertion · rank 1
CVSS:4.0/AV:N/AC:L/AT:P/PR:H/UI:N/VC:N/VI:H/VA:N/SC:N/SI:N/SA:N/AU:N/R:U/V:C/RE:H/U:Red- Validation
- Valid match
- Recomputed
- 5.9
- Decision reason
- Evidence supported
- Policy
- casca-direct-cvss-eligibility-v1
palo_alto
CVSS 4.0 · Primary · Original assertion · rank 1
CVSS:4.0/AV:N/AC:L/AT:N/PR:H/UI:N/VC:N/VI:H/VA:N/SC:N/SI:N/SA:N/AU:N/R:U/V:C/RE:H/U:Red- Validation
- Valid match
- Recomputed
- 6.9
- Decision reason
- Evidence supported
- Policy
- casca-direct-cvss-eligibility-v1
Assessments are retained side by side under closed precedence. Cascade never averages CVSS.
Evidence boundaries
- KEV membership is authoritative for the catalog, not proof of exposure in any environment.
- EPSS is a dated model probability and not an individual-environment prediction.
- Affected or fixed status applies only to the exact cited product and version scope; remaining scope stays source-scoped.
- NVD-carried upstream facts remain derivative; independent corroboration requires a separately authored source.
- Only NVD metrics validated under the generation-bound calculator are Public Priority eligible; direct CVE record metrics remain display-only.
- NVD CVSS source eligibility is closed: NVD-authored, exact record-source, or registered same-CVE container origin; unmapped sources remain display-only.
- Core replay supports the active and immediately prior generation; retrospective valid-at replay is deferred.
- OSV aggregation and OSV-converted NVD material are not independent corroboration.
- Red Hat facts are vendor assertions for the exact supplied products.
- Nonmembership and not-yet-observed states are not proof of safety.