Vulnerability Description
A privilege escalation (PE) vulnerability in the XML API of Palo Alto Networks PAN-OS software enables an authenticated PAN-OS administrator with restricted privileges to use a compromised XML API key to perform actions as a higher privileged PAN-OS administrator. For example, an administrator with "Virtual system administrator (read-only)" access could use an XML API key of a "Virtual system administrator" to perform write operations on the virtual system configuration even though they should be limited to read-only operations.
CVSS Score
MEDIUM
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Paloaltonetworks | Pan-Os | >= 9.0.0, < 10.0.0 |
Related Weaknesses (CWE)
References
- https://security.paloaltonetworks.com/CVE-2024-9471Vendor Advisory
FAQ
What is CVE-2024-9471?
CVE-2024-9471 is a vulnerability with a CVSS score of 4.7 (MEDIUM). A privilege escalation (PE) vulnerability in the XML API of Palo Alto Networks PAN-OS software enables an authenticated PAN-OS administrator with restricted privileges to use a compromised XML API key...
How severe is CVE-2024-9471?
CVE-2024-9471 has been rated MEDIUM with a CVSS base score of 4.7/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2024-9471?
Check the references section above for vendor advisories and patch information. Affected products include: Paloaltonetworks Pan-Os.