CVE-2024-9471
CVSS 3.1 Score 4.7 of 10 (medium)
Details
Summary
CVE-2024-9471 is a newly disclosed privilege escalation vulnerability affecting the XML API of Palo Alto Networks PAN-OS software. This issue enables authenticated PAN-OS administrators with restricted privileges to perform actions beyond their authorized level using a compromised XML API key. For instance, an administrator with read-only access can exploit this vulnerability to execute write operations on the virtual system configuration, bypassing the intended access restrictions. Such unauthorized actions could lead to significant security risks and potential data breaches. Organizations utilizing PAN-OS are urged to apply the available patch to mitigate this vulnerability.
Prevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.
Affected Products
- PAN-OS
Affected Vendors
- Palo Alto Networks