enterprise data management

When CVSS Scores Disagree, Chained Vulnerabilities Handed Attackers Root Access

In November 2024, during Operation Lunar Peek, attackers exploited two CVEs in Palo Alto Networks systems, granting them root access to over 13,000 devices.

3 min readVentureBeat
When CVSS Scores Disagree, Chained Vulnerabilities Handed Attackers Root Access

CVSS scores told the truth: CVE-2024-9474 scored 6.9, and that score was useless. The problem is not that the scoring system lied; the problem is that organizations built their entire prioritization pipeline around a metric designed to evaluate one vulnerability in isolation, while adversaries chain two, three, or four together without ever checking a score sheet.

The Palo Alto Networks operation in November 2024 is the cleanest example of a failure mode that repeats across every major breach this year. Authentication bypass scored 9.3; privilege escalation scored 6.9. Any triage system that filters below a 7.0 threshold deprioritized the escalation flaw because admin access appeared required. The authentication bypass eliminated that prerequisite. No score communicated the compound effect. CrowdStrike's Adam Meyers described the operational psychology precisely: teams assessed each CVE independently, deprioritized the lower score, and queued the higher one for maintenance. The triage system had amnesia from 30 seconds before.

For security directors, the practical implication is that your current prioritization method has already failed, and the data proving it exists in your own queue. Every KEV CVE in your environment should trigger a chain-dependency audit this month. Flag any co-resident CVE scored 5.0 or above, the threshold where privilege escalation capabilities typically appear. Any pair chaining authentication bypass to privilege escalation gets triaged as critical regardless of individual scores. The CVSS vector strings contain the information you need; the aggregate score suppresses it. Stop consuming the aggregate number and start reading the vector.

The infrastructure behind the scores is buckling. NVD enrichment is now restricted to KEV and federal critical software because CVE submissions have grown 263% since 2020. Jerry Gamblin projects 70,135 CVEs for 2026. Frontier AI models can discover vulnerabilities at a total compute cost under $20,000. If autonomous discovery drives a 10x volume increase, your pipeline built for 48,000 CVEs breaks at 70,000 and collapses at 480,000. CrowdStrike, Accenture, EY, IBM, Kroll, and OpenAI formed a remediation coalition around a problem no single organization's patch workflow can outrun. Present the capacity gap to your CFO before the next budget cycle, not after the breach that proves the gap existed.

From VentureBeat

During Operation Lunar Peek in November 2024, attackers gained unauthenticated remote admin access — and eventual root — across more than 13,000 exposed Palo Alto Networks management interfaces. Palo Alto Networks scored CVE-2024-0012 at 9.3 and CVE-2024-9474 at 6.9 under CVSS v4.0. NVD scored the same pair 9.8 and 7.2 under CVSS v3.1. Two scoring systems. Two different answers for the same vulnerabilities. The 6.9 fell below patch thresholds. Admin access appeared required. The 9.3 sat queued for maintenance. Segmentation would hold.

Read the original at VentureBeat