CVE-2024-0012

Confirmed PUBLISHED

PAN-OS: Authentication Bypass in the Management Web Interface (PAN-SA-2024-0015)

Palo Alto Networks · Cloud NGFW, PAN-OS, Prisma Access
Exploited in the wild Used in malware PoC available

Recommended Action

Prioritize remediation. Validate affected assets and apply vendor fixes on an accelerated timeline.

Confidence
Confirmed
Exploitation Status
Exploited in the wild
Observed in Sensors
No
Attempts (30d)
Unique Attacker IPs
CISA KEV
In CISA KEV
CVSS / EPSS
9.3 Critical EPSS 99.7%

At a Glance

An authentication bypass in Palo Alto Networks PAN-OS software enables an unauthenticated attacker with network access to the management web interface to gain PAN-OS administrator privileges to perform administrative actions, tamper with the configuration, or exploit other authenticated privilege escalation vulnerabilities like CVE-2024-9474 https://security.paloaltonetworks.com/CVE-2024-9474 . The risk of this issue is greatly reduced if you secure access to the management web interface by restricting access to only trusted internal IP addresses according to our recommended  best practice deployment guidelines https://live.paloaltonetworks.com/t5/community-blogs/tips-amp-tricks-how-to-secure-the-management-access-of-your-palo/ba-p/464431 . This issue is applicable only to PAN-OS 10.2, PAN-OS 11.0, PAN-OS 11.1, and PAN-OS 11.2 software. Cloud NGFW and Prisma Access are not impacted by this vulnerability.

nuclei_scanner nessus_scanner edge metasploit cisa malware
CVE Published
Nov 18, 2024
Exploitation Reported
Nov 18, 2024
CVSS
9.3 Critical
EPSS
99.7%
Remote Low complexity No user interaction Unauthenticated

Affected Versions

Vendor Product Version Status
Palo Alto Networks
Cloud NGFW

All

Unaffected
Palo Alto Networks
PAN-OS

11.2.0 to < 11.2.4-h1

Changed to unaffected at 11.2.4-h1

Affected
Palo Alto Networks
PAN-OS

11.1.0 to < 11.1.5-h1

Changed to unaffected at 11.1.5-h1

Affected
Palo Alto Networks
PAN-OS

11.0.0 to < 11.0.6-h1

Changed to unaffected at 11.0.6-h1

Affected
Palo Alto Networks
PAN-OS

10.2.0 to < 10.2.12-h2

Changed to unaffected at 10.2.12-h2

Affected
Palo Alto Networks
PAN-OS

10.1.0

Unaffected
Palo Alto Networks
Prisma Access

All

Unaffected

CVE References

Recommended Actions

  • Prioritize remediation. Validate affected assets and apply vendor fixes on an accelerated timeline.
  • Check enrichment artifacts for scanner coverage and available PoCs before rolling remediation validation.
  • Use the Pro API to automate enrichment, telemetry, and workflow delivery for VM, SOC, and CTI pipelines.