Vulnerability Monitor

The vendors, products, and vulnerabilities you care about

CVE-2024-9471


A privilege escalation (PE) vulnerability in the XML API of Palo Alto Networks PAN-OS software enables an authenticated PAN-OS administrator with restricted privileges to use a compromised XML API key to perform actions as a higher privileged PAN-OS administrator. For example, an administrator with "Virtual system administrator (read-only)" access could use an XML API key of a "Virtual system administrator" to perform write operations on the virtual system configuration even though they should be limited to read-only operations.


Published

2024-10-09T17:15:21.090

Last Modified

2024-10-15T16:55:45.090

Status

Analyzed

Source

[email protected]

Severity

CVSSv3.1: 4.7 (MEDIUM)

Weaknesses
  • Type: Secondary
    CWE-269
  • Type: Primary
    NVD-CWE-noinfo

Affected Vendors & Products
Type Vendor Product Version/Range Vulnerable?
Operating System paloaltonetworks pan-os < 10.0.0 Yes
Operating System paloaltonetworks pan-os < 10.1.11 Yes
Operating System paloaltonetworks pan-os < 10.2.8 Yes
Operating System paloaltonetworks pan-os < 11.0.3 Yes

References