CVE-2024-9471

PAN-OS: Privilege Escalation (PE) Vulnerability in XML API

Severity
Medium 5.1
CVSS 4.0
Exploited
Not listed
EPSS
0.003
22.3th percentile
Discovered by
Third party
Vendor-published field
Published
Oct 9, 2024
Assigned by palo_alto

Description

A privilege escalation (PE) vulnerability in the XML API of Palo Alto Networks PAN-OS software enables an authenticated PAN-OS administrator with restricted privileges to use a compromised XML API key to perform actions as a higher privileged PAN-OS administrator. For example, an administrator with "Virtual system administrator (read-only)" access could use an XML API key of a "Virtual system administrator" to perform write operations on the virtual system configuration even though they should be limited to read-only operations.

Weakness: CWE-269

Affected products

Vendor Product Category Matched by
Palo Alto Networks PAN-OS Firewall / NGFW cna-assigner
Vendor-reported products (4)
  • Palo Alto Networks · PAN-OS
  • Palo Alto Networks · Cloud NGFW — vendor states not affected
  • Palo Alto Networks · Prisma Access — vendor states not affected
  • paloaltonetworks · pan-os

Credit

Palo Alto Networks thanks an external reporter for discovering and reporting this issue.

Vendor remediation

This issue is fixed in PAN-OS 10.1.11, PAN-OS 10.2.8, PAN-OS 11.0.3, and all later PAN-OS versions.

Something wrong here?