Vulnerability record · CVE-2024-0012 · published 18 November 2024
CVE-2024-0012: PAN-OS Management Web Interface Authentication Bypass
Paloaltonetworks · Pan Os
PAN-OS contains a missing authentication flaw (CWE-306) in the management web interface that lets an unauthenticated network attacker obtain PAN-OS administrator privileges. Because it grants full administrative control, it can be used to alter configuration or chain into authenticated privilege escalation issues such as CVE-2024-9474. Only PAN-OS 10.2, 11.0, 11.1, and 11.2 are affected; Cloud NGFW and Prisma Access are not.
Description
An authentication bypass in Palo Alto Networks PAN-OS software enables an unauthenticated attacker with network access to the management web interface to gain PAN-OS administrator privileges to perform administrative actions, tamper with the configuration, or exploit other authenticated privilege escalation vulnerabilities like CVE-2024-9474 https://security.paloaltonetworks.com/CVE-2024-9474 . The risk of this issue is greatly reduced if you secure access to the management web interface by restricting access to only trusted internal IP addresses according to our recommended best practice deployment guidelines https://live.paloaltonetworks.com/t5/community-blogs/tips-amp-tricks-how-to-secure-the-management-access-of-your-palo/ba-p/464431 . This issue is applicable only to PAN-OS 10.2, PAN-OS 11.0, PAN-OS 11.1, and PAN-OS 11.2 software. Cloud NGFW and Prisma Access are not impacted by this vulnerability.
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:L/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:N/R:
Automated analysis
critical priorityUnauthenticated network-reachable admin takeover with CVSS 9.3, KEV listing, ransomware use, and near-certain EPSS exploitation probability.
What it is
PAN-OS contains a missing authentication flaw (CWE-306) in the management web interface that lets an unauthenticated network attacker obtain PAN-OS administrator privileges. Because it grants full administrative control, it can be used to alter configuration or chain into authenticated privilege escalation issues such as CVE-2024-9474. Only PAN-OS 10.2, 11.0, 11.1, and 11.2 are affected; Cloud NGFW and Prisma Access are not.
Impact
An attacker gains PAN-OS administrator privileges, enabling configuration tampering and administrative actions, and can pivot to further authenticated privilege escalation vulnerabilities. This effectively hands over control of the firewall's management plane.
Attack surface
Reached over the network via the management web interface (CVSS 4.0 AV:N, PR:N, UI:N), so no authentication or user interaction is required. Exposure is limited to management interfaces reachable by the attacker; restricting management access to trusted internal IPs greatly reduces risk.
Exploitation
CISA added it to KEV on 2024-11-18 with a 2024-12-09 remediation due date and flags known ransomware campaign use; EPSS 30-day probability is 0.99718 (99.951st percentile), and a third-party advisory is tagged Exploit.
What to do
- Apply the vendor patches for PAN-OS 10.2, 11.0, 11.1, and 11.2 per the Palo Alto Networks advisory.
- Immediately restrict management web interface access to trusted internal IP addresses only; do not expose it to the internet or untrusted networks.
- If patching is not immediately possible, follow vendor mitigation guidance or discontinue use of the affected product as directed by CISA.
- Audit for signs of prior compromise and rotate administrative credentials after remediation.
- Verify Cloud NGFW and Prisma Access are unaffected and exclude them from emergency change scope.
Detection
- Monitor management web interface access logs for unauthenticated or anomalous requests, especially from unexpected source IPs.
- Alert on new or modified administrative accounts, configuration changes, and unexpected admin logins on PAN-OS devices.
- Hunt for exploitation attempts and post-exploitation activity tied to CVE-2024-0012 and chained CVE-2024-9474 using the Unit 42 and WatchTowr technical write-ups.
- Review network exposure to confirm no management interface is reachable from untrusted networks.
This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.
Exploitation in the wild
CISA added CVE-2024-0012 to the Known Exploited Vulnerabilities catalog on 18 November 2024 as "Palo Alto Networks PAN-OS Management Interface Authentication Bypass Vulnerability". CISA reports known use in ransomware campaigns. Required action: Apply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable. Additionally, management interface for affected devices should not be exposed to untrusted networks, including the internet. Federal deadline 9 December 2024.
Affected products
1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.
References
| Link | Tags |
|---|---|
| https://security.paloaltonetworks.com/CVE-2024-0012 | Vendor Advisory |
| https://unit42.paloaltonetworks.com/cve-2024-0012-cve-2024-9474/ | Vendor Advisory |
| https://labs.watchtowr.com/pots-and-pans-aka-an-sslvpn-palo-alto-pan-os-cve-2024-0012-and-cve-2024-9474/ | ExploitThird Party Advisory |
| https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2024-0012 | US Government Resource |
Track CVE-2024-0012 inside VULONE
Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.
Related vulnerabilities
Same products first, then exploited flaws of the same weakness class.
Source: NIST National Vulnerability Database (record CVE-2024-0012), CISA KEV, FIRST EPSS (scores of 2026-09-24). This page is refreshed as NVD updates the record.