Critical [CVE-2024-0012 +1] PAN-OS: Authentication Bypass in the Management Web Interface (PAN-SA-2024-0015)
This critical-severity Palo Alto Networks advisory covers CVE-2024-0012 and CVE-2024-9474 affecting PAN-OS.
Android app · Google Play
Monitor future Palo Alto Networks CVEs from your phone.
Choose a whole vendor or a precise platform, then receive matching security advisories by phone notification, email, or both. Coverage follows 32 official vendor sources and 160+ reviewed platform categories.
Summary
An authentication bypass in Palo Alto Networks PAN-OS software enables an unauthenticated attacker with network access to the management web interface to gain PAN-OS administrator privileges to perform administrative actions, tamper with the configuration, or exploit other authenticated privilege escalation vulnerabilities like CVE-2024-9474.
The risk of this issue is greatly reduced if you secure access to the management web interface by restricting access to only trusted internal IP addresses according to our recommended best practice deployment guidelines.
This issue is applicable only to PAN-OS 10.2, PAN-OS 11.0, PAN-OS 11.1, and PAN-OS 11.2 software on PA-Series, VM-Series, and CN-Series firewalls and on Panorama (virtual and M-Series). Cloud NGFW and Prisma Access are not impacted by this vulnerability.
CISA Known Exploited Vulnerability
- Listed:
- Nov 18, 2024 · federal remediation due Dec 9, 2024
- Required action:
- Apply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable. Additionally, management interface for affected devices should not be exposed to untrusted networks, including the internet.
- Ransomware use:
- Known
KEV is a prioritization signal from CISA — remediation detail still comes from the vendor advisory.
- PAN-OS 11.2: < 11.2.0-h1< 11.2.1-h1< 11.2.2-h2< 11.2.3-h3< 11.2.4-h1
- PAN-OS 11.1: < 11.1.0-h4< 11.1.1-h2< 11.1.2-h15< 11.1.3-h11< 11.1.4-h7< 11.1.5-h1
- PAN-OS 11.0: < 11.0.0-h4< 11.0.1-h5< 11.0.2-h5< 11.0.3-h13< 11.0.4-h6< 11.0.5-h2< 11.0.6-h1
- PAN-OS 10.2: < 10.2.0-h4< 10.2.1-h3< 10.2.2-h6< 10.2.3-h14< 10.2.4-h32< 10.2.5-h9< 10.2.6-h6< 10.2.7-h18< 10.2.8-h15< 10.2.9-h16< 10.2.10-h9< 10.2.11-h6< 10.2.12-h2
Official advisory · high-confidence parse· fetched 1 hour ago·verify at source
- PAN-OS 11.2: >= 11.2.0-h1>= 11.2.1-h1>= 11.2.2-h2>= 11.2.3-h3>= 11.2.4-h1
- PAN-OS 11.1: >= 11.1.0-h4>= 11.1.1-h2>= 11.1.2-h15>= 11.1.3-h11>= 11.1.4-h7>= 11.1.5-h1
- PAN-OS 11.0: >= 11.0.0-h4>= 11.0.1-h5>= 11.0.2-h5>= 11.0.3-h13>= 11.0.4-h6>= 11.0.5-h2>= 11.0.6-h1
- PAN-OS 10.2: >= 10.2.0-h4>= 10.2.1-h3>= 10.2.2-h6>= 10.2.3-h14>= 10.2.4-h32>= 10.2.5-h9>= 10.2.6-h6>= 10.2.7-h18>= 10.2.8-h15>= 10.2.9-h16>= 10.2.10-h9>= 10.2.11-h6>= 10.2.12-h2
Official advisory · high-confidence parse· fetched 1 hour ago·verify at source
Mitigation checklist
- We strongly recommend that you secure access to your management interface following the instructions in the workarounds section below.
- This issue is fixed in PAN-OS 10.2.12-h2, PAN-OS 11.0.6-h1, PAN-OS 11.1.5-h1, PAN-OS 11.2.4-h1, and all later PAN-OS versions.
- In addition, in an attempt to provide the most seamless upgrade path for our customers, we are making fixes available for other TAC-preferred and commonly deployed maintenance releases.
- Recommended mitigation—The vast majority of firewalls already follow Palo Alto Networks and industry best practices.
- However, if you haven’t already, we strongly recommend that you secure access to your management interface according to our best practice deployment guidelines.
- Specifically, you should restrict access to the management interface to only trusted internal IP addresses to prevent external access from the internet.
- Additionally, if you have a Threat Prevention subscription, you can block these attacks using Threat IDs 95746, 95747, 95752, 95753, 95759, and 95763 (available in Applications and Threats content version 8915-9075 and later).
- For these Threat IDs to protect against attacks for this vulnerability,
Official advisory · high-confidence parse· fetched 1 hour ago·verify at source
Discussion(0)
No comments yet. Share field notes, upgrade gotchas, or questions — verify against the vendor advisory before acting on community advice.
Sign in to join the discussion.