← Vulnerability feed

Vulnerability record · CVE-2024-0012 · published 18 November 2024

CVE-2024-0012: PAN-OS Management Web Interface Authentication Bypass

Paloaltonetworks · Pan Os

PAN-OS contains a missing authentication flaw (CWE-306) in the management web interface that lets an unauthenticated network attacker obtain PAN-OS administrator privileges. Because it grants full administrative control, it can be used to alter configuration or chain into authenticated privilege escalation issues such as CVE-2024-9474. Only PAN-OS 10.2, 11.0, 11.1, and 11.2 are affected; Cloud NGFW and Prisma Access are not.

9.3 CVSS 4.0 Critical CISA KEV since 18 Nov 2024 Known ransomware use EPSS 100% · top 0.1% CWE-306 · Missing authentication for critical function
9.3CVSS 4.0 base score
100%EPSS exploitation probability, 30 days
YesIn CISA KEV, fix deadline passed
1Affected product versions listed by NVD
4References, 1 tagged exploit
4 Aug 2026Last modified by NVD

Description

An authentication bypass in Palo Alto Networks PAN-OS software enables an unauthenticated attacker with network access to the management web interface to gain PAN-OS administrator privileges to perform administrative actions, tamper with the configuration, or exploit other authenticated privilege escalation vulnerabilities like CVE-2024-9474 https://security.paloaltonetworks.com/CVE-2024-9474 . The risk of this issue is greatly reduced if you secure access to the management web interface by restricting access to only trusted internal IP addresses according to our recommended  best practice deployment guidelines https://live.paloaltonetworks.com/t5/community-blogs/tips-amp-tricks-how-to-secure-the-management-access-of-your-palo/ba-p/464431 . This issue is applicable only to PAN-OS 10.2, PAN-OS 11.0, PAN-OS 11.1, and PAN-OS 11.2 software. Cloud NGFW and Prisma Access are not impacted by this vulnerability.

CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:L/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:N/R:

Automated analysis

Generated by VULONE's analysis model from the NVD record, CISA KEV and EPSS data on 16 September 2026. Confidence: high.

critical priorityUnauthenticated network-reachable admin takeover with CVSS 9.3, KEV listing, ransomware use, and near-certain EPSS exploitation probability.

What it is

PAN-OS contains a missing authentication flaw (CWE-306) in the management web interface that lets an unauthenticated network attacker obtain PAN-OS administrator privileges. Because it grants full administrative control, it can be used to alter configuration or chain into authenticated privilege escalation issues such as CVE-2024-9474. Only PAN-OS 10.2, 11.0, 11.1, and 11.2 are affected; Cloud NGFW and Prisma Access are not.

Impact

An attacker gains PAN-OS administrator privileges, enabling configuration tampering and administrative actions, and can pivot to further authenticated privilege escalation vulnerabilities. This effectively hands over control of the firewall's management plane.

Attack surface

Reached over the network via the management web interface (CVSS 4.0 AV:N, PR:N, UI:N), so no authentication or user interaction is required. Exposure is limited to management interfaces reachable by the attacker; restricting management access to trusted internal IPs greatly reduces risk.

Exploitation

CISA added it to KEV on 2024-11-18 with a 2024-12-09 remediation due date and flags known ransomware campaign use; EPSS 30-day probability is 0.99718 (99.951st percentile), and a third-party advisory is tagged Exploit.

What to do

  • Apply the vendor patches for PAN-OS 10.2, 11.0, 11.1, and 11.2 per the Palo Alto Networks advisory.
  • Immediately restrict management web interface access to trusted internal IP addresses only; do not expose it to the internet or untrusted networks.
  • If patching is not immediately possible, follow vendor mitigation guidance or discontinue use of the affected product as directed by CISA.
  • Audit for signs of prior compromise and rotate administrative credentials after remediation.
  • Verify Cloud NGFW and Prisma Access are unaffected and exclude them from emergency change scope.

Detection

  • Monitor management web interface access logs for unauthenticated or anomalous requests, especially from unexpected source IPs.
  • Alert on new or modified administrative accounts, configuration changes, and unexpected admin logins on PAN-OS devices.
  • Hunt for exploitation attempts and post-exploitation activity tied to CVE-2024-0012 and chained CVE-2024-9474 using the Unit 42 and WatchTowr technical write-ups.
  • Review network exposure to confirm no management interface is reachable from untrusted networks.

This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.

Exploitation in the wild

CISA added CVE-2024-0012 to the Known Exploited Vulnerabilities catalog on 18 November 2024 as "Palo Alto Networks PAN-OS Management Interface Authentication Bypass Vulnerability". CISA reports known use in ransomware campaigns. Required action: Apply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable. Additionally, management interface for affected devices should not be exposed to untrusted networks, including the internet. Federal deadline 9 December 2024.

Affected products

1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

Track CVE-2024-0012 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

10.0CVE-2024-3400PAN-OS GlobalProtect command injection allows unauthenticated root code executionA command injection caused by arbitrary file creation in the GlobalProtect feature of Palo Alto Networks PAN-OS lets an unauthenticated attacker run …KEVEPSS 100%analysed10.0CVE-2020-2021PAN-OS SAML signature verification bypass allows authentication bypassPAN-OS fails to properly verify SAML signatures when SAML authentication is enabled and the 'Validate Identity Provider Certificate' option is unchec…KEVEPSS 4.4%analysed9.8CVE-2017-15944PAN-OS management interface input validation flaw allows remote code executionPAN-OS versions before 6.1.19, 7.0.x before 7.0.19, 7.1.x before 7.1.14, and 8.0.x before 8.0.6 contain an input validation and memory buffer overflo…KEVEPSS 98%analysed9.3CVE-2026-0300PAN-OS User-ID Authentication Portal buffer overflow allows root code executionA buffer overflow (out-of-bounds write, CWE-787) in the User-ID Authentication Portal (Captive Portal) service of Palo Alto Networks PAN-OS lets an u…KEVEPSS 32%analysed8.8CVE-2025-0108PAN-OS management web interface authentication bypassPAN-OS contains a missing-authentication flaw (CWE-306) in the management web interface that lets an unauthenticated attacker with network access inv…KEVEPSS 98%analysed8.7CVE-2024-3393PAN-OS DNS Security packet causes firewall reboot and maintenance modeA denial of service flaw in the DNS Security feature of Palo Alto Networks PAN-OS lets an unauthenticated attacker send a crafted packet through the …KEVEPSS 28%analysed8.6CVE-2022-0028PAN-OS URL filtering misconfiguration enables reflected TCP DoSA PAN-OS URL filtering policy misconfiguration allows a network-based attacker to use PA-Series, VM-Series and CN-Series firewalls to conduct reflect…KEVEPSS 2.4%analysed8.1CVE-2019-1579PAN-OS GlobalProtect pre-auth remote code executionPAN-OS versions 7.1.18, 8.0.11-h1 and 8.1.2 and earlier contain a remote code execution flaw (CWE-134, format string) that is reachable when the Glob…KEVEPSS 46%analysed

Source: NIST National Vulnerability Database (record CVE-2024-0012), CISA KEV, FIRST EPSS (scores of 2026-09-24). This page is refreshed as NVD updates the record.