Executive brief
A privilege escalation vulnerability in Palo Alto Networks PAN-OS software allows an administrator with access to the management web interface to perform actions with root privileges via OS command injection. This vulnerability has been observed being exploited in the wild.
Affected products
- Palo Alto Networks PAN-OS 10.1.0 to < 10.1.14-h6, 10.2.0 to < 10.2.12-h2, 11.0.0 to < 11.0.6-h1, 11.1.0 to < 11.1.5-h1, 11.2.0 to < 11.2.4-h1
Timeline
- 2024-11-18: disclosed
- 2024-11-18: advisory
- 2024-11-18: kev added: Added to CISA KEV catalog due to active exploitation.
- 2024-11-18: exploited