What breaks and who should care
If your scanner has just flagged CVE-2024-9474, you are looking at a serious weakness in the web‑based management interface of PAN‑OS devices. Any firewall, VPN concentrator or similar appliance running the vulnerable releases can be forced to execute arbitrary operating‑system commands. That means an attacker who can reach the management UI could climb from a low‑privilege web user to full control of the appliance.
Related remediation guides
Other vulnerabilities in the same family or affecting the same products:
- CVE-2024-0012 – PAN‑OS authentication bypass – immediate actions
- Ivanti EPMM CVE-2026-6973 RCE Under Active Exploitation
- CVE-2025-59528 – Immediate steps for Flowise remote code execution
We keep a daily-updated list of vulnerabilities CISA has confirmed as actively exploited, including remediation deadlines.
Why the vulnerability matters
The Common Vulnerability Scoring System rates this flaw at 7.2, placing it in the high severity band. A score of that level signals a clear path to privilege escalation, and the public record shows it has already been used in ransomware campaigns. CISA has listed it as a known exploited vulnerability and demands immediate mitigation.
Technical class and mechanism
The NVD description identifies this as an OS command injection vulnerability. In plain terms, the web management component accepts input that is later passed to the underlying operating system without proper sanitisation. An attacker can embed shell commands in a request, and the device will run them with the privileges of the management service.
Because the exact request format and vulnerable parameter have not been disclosed, we cannot give a step‑by‑step exploit recipe. The vulnerability class is well understood: unsanitised user input reaches a system‑level call such as system() or exec(). The result is that any command the attacker can write into the request will be executed on the device.
Real‑world impact
Successful exploitation gives the attacker the ability to:
- Read or modify configuration files, including firewall rules and VPN settings.
- Install additional software or back‑doors on the appliance.
- Disrupt network traffic by changing routing or policy.
- Use the compromised device as a foothold for lateral movement inside the organisation.
In the wild, threat actors have paired this flaw with ransomware payloads. The compromise of a perimeter firewall can give them a direct route to encrypt critical systems, demanding a ransom.
How to determine if you are exposed
The first step is to verify the PAN‑OS version running on each appliance. The version string is displayed in the web UI footer and can also be obtained via the CLI:
show system info | match "Version"
If the version you see falls into any of the ranges listed in the table below, your device is vulnerable.
Next, confirm whether the management interface is reachable from untrusted networks. Run a simple port scan from a host outside your trusted zone targeting the HTTPS management port (default 443). If the port is open, the attack surface is exposed.
Mitigation steps
There are three practical paths to protect yourself:
1. Apply the vendor patch
The safest and quickest remedy is to upgrade to the patched release for your branch. The table below shows which releases contain the fix. Schedule a maintenance window, back up the configuration, and follow Palo Alto Networks’ upgrade guide. After the upgrade, re‑run the version check to confirm the new release is active.
2. Reduce exposure of the management UI
If you cannot patch immediately, isolate the management interface:
- Restrict inbound traffic to the management IP address to a limited set of trusted hosts.
- Place the device behind a jump host or bastion that requires multi‑factor authentication.
- Disable remote access over the internet entirely; use a VPN that terminates on a trusted network before reaching the UI.
These steps do not eliminate the flaw, but they make it much harder for an attacker to reach the vulnerable code.
3. Apply vendor‑provided mitigations
Palo Alto Networks has published a set of configuration hardening recommendations for this issue. They include:
- Enabling strict input validation on the web management service.
- Turning on the built‑in command‑injection protection flag (if available). The exact CLI toggle can be found in the release notes for the patched branch.
- Ensuring that the management plane runs with the lowest possible privileges.
Implement these settings as soon as you can, and document the changes for audit purposes.
What to do if a patch is unavailable
In the rare case that your environment cannot be upgraded—for example, a legacy appliance that is end‑of‑life—you must treat the device as an untrusted asset. Options include:
- Segregating the appliance into a dedicated VLAN with no internet access.
- Deploying a network‑level intrusion‑prevention system that blocks suspicious HTTP methods and payloads targeting the management URL.
- Monitoring logs for any unusual command execution attempts. The CLI command
show log systemwill reveal anomalies such as unexpected process launches.
Ultimately, replacing the hardware with a supported version that receives security updates is the most reliable long‑term solution.
Compliance and reporting
CISA’s directive requires organisations to either apply the mitigations or discontinue use of the product. Record the steps you have taken in your vulnerability management system. If you are subject to regulatory frameworks that demand proof of remediation, keep screenshots of the version check, the configuration changes, and the upgrade logs.
Summary of actions
- Run
show system info | match "Version"on each PAN‑OS device. - Compare the output against the table below to see if you fall in the vulnerable range.
- If vulnerable, upgrade to the patched release for your branch as soon as possible.
- If you cannot patch, restrict management access to trusted networks only.
- Apply any vendor‑issued hardening settings immediately.
- Document every step for audit and compliance purposes.
Time is of the essence. The vulnerability has already been weaponised in ransomware attacks, and the only reliable defence is to move to a version that contains the fix. Use the table below as your reference point and act now.
Affected versions
Straight from the NVD record for CVE-2024-9474. If your build is inside one of these ranges, treat it as vulnerable.
| Product | Affected range | Fixed in |
|---|---|---|
pan-os |
10.1.0 up to 10.1.14 | 10.1.14 |
pan-os |
10.2.0 up to 10.2.12 | 10.2.12 |
pan-os |
11.0.0 up to 11.0.6 | 11.0.6 |
pan-os |
11.1.0 up to 11.1.5 | 11.1.5 |
pan-os |
11.2.0 up to 11.2.4 | 11.2.4 |


