Skip to content
VulniPulse
Critical9.3Palo Alto Networks PoC reported CISA KEV

Critical [CVE-2024-0012 +1] PAN-OS: Authentication Bypass in the Management Web Interface (PAN-SA-2024-0015)

This critical-severity Palo Alto Networks advisory covers CVE-2024-0012 and CVE-2024-9474 affecting PAN-OS.

CVE-2024-0012 Published Nov 18, 2024Updated by vendor Aug 4, 2026
Affected products & platforms
Palo Alto NetworksPAN-OSFirewallCloud NGFWPAN-OS / Panorama
Open vendor advisory

Android app · Google Play

Monitor future Palo Alto Networks CVEs from your phone.

Choose a whole vendor or a precise platform, then receive matching security advisories by phone notification, email, or both. Coverage follows 32 official vendor sources and 160+ reviewed platform categories.

Matching phone alertsOptional email delivery

Summary

An authentication bypass in Palo Alto Networks PAN-OS software enables an unauthenticated attacker with network access to the management web interface to gain PAN-OS administrator privileges to perform administrative actions, tamper with the configuration, or exploit other authenticated privilege escalation vulnerabilities like CVE-2024-9474.

The risk of this issue is greatly reduced if you secure access to the management web interface by restricting access to only trusted internal IP addresses according to our recommended best practice deployment guidelines.

This issue is applicable only to PAN-OS 10.2, PAN-OS 11.0, PAN-OS 11.1, and PAN-OS 11.2 software on PA-Series, VM-Series, and CN-Series firewalls and on Panorama (virtual and M-Series). Cloud NGFW and Prisma Access are not impacted by this vulnerability.

CISA Known Exploited Vulnerability

Listed:
Nov 18, 2024 · federal remediation due Dec 9, 2024
Required action:
Apply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable. Additionally, management interface for affected devices should not be exposed to untrusted networks, including the internet.
Ransomware use:
Known

KEV is a prioritization signal from CISA — remediation detail still comes from the vendor advisory.

Affected versions
  • PAN-OS 11.2: < 11.2.0-h1< 11.2.1-h1< 11.2.2-h2< 11.2.3-h3< 11.2.4-h1
  • PAN-OS 11.1: < 11.1.0-h4< 11.1.1-h2< 11.1.2-h15< 11.1.3-h11< 11.1.4-h7< 11.1.5-h1
  • PAN-OS 11.0: < 11.0.0-h4< 11.0.1-h5< 11.0.2-h5< 11.0.3-h13< 11.0.4-h6< 11.0.5-h2< 11.0.6-h1
  • PAN-OS 10.2: < 10.2.0-h4< 10.2.1-h3< 10.2.2-h6< 10.2.3-h14< 10.2.4-h32< 10.2.5-h9< 10.2.6-h6< 10.2.7-h18< 10.2.8-h15< 10.2.9-h16< 10.2.10-h9< 10.2.11-h6< 10.2.12-h2

Official advisory · high-confidence parse· fetched 1 hour ago·verify at source

Fixed versions
  • PAN-OS 11.2: >= 11.2.0-h1>= 11.2.1-h1>= 11.2.2-h2>= 11.2.3-h3>= 11.2.4-h1
  • PAN-OS 11.1: >= 11.1.0-h4>= 11.1.1-h2>= 11.1.2-h15>= 11.1.3-h11>= 11.1.4-h7>= 11.1.5-h1
  • PAN-OS 11.0: >= 11.0.0-h4>= 11.0.1-h5>= 11.0.2-h5>= 11.0.3-h13>= 11.0.4-h6>= 11.0.5-h2>= 11.0.6-h1
  • PAN-OS 10.2: >= 10.2.0-h4>= 10.2.1-h3>= 10.2.2-h6>= 10.2.3-h14>= 10.2.4-h32>= 10.2.5-h9>= 10.2.6-h6>= 10.2.7-h18>= 10.2.8-h15>= 10.2.9-h16>= 10.2.10-h9>= 10.2.11-h6>= 10.2.12-h2

Official advisory · high-confidence parse· fetched 1 hour ago·verify at source

Mitigation checklist

Recommended fix / mitigation
  • We strongly recommend that you secure access to your management interface following the instructions in the workarounds section below.
  • This issue is fixed in PAN-OS 10.2.12-h2, PAN-OS 11.0.6-h1, PAN-OS 11.1.5-h1, PAN-OS 11.2.4-h1, and all later PAN-OS versions.
  • In addition, in an attempt to provide the most seamless upgrade path for our customers, we are making fixes available for other TAC-preferred and commonly deployed maintenance releases.
Temporary workarounds
  • Recommended mitigation—The vast majority of firewalls already follow Palo Alto Networks and industry best practices.
  • However, if you haven’t already, we strongly recommend that you secure access to your management interface according to our best practice deployment guidelines.
  • Specifically, you should restrict access to the management interface to only trusted internal IP addresses to prevent external access from the internet.
  • Additionally, if you have a Threat Prevention subscription, you can block these attacks using Threat IDs 95746, 95747, 95752, 95753, 95759, and 95763 (available in Applications and Threats content version 8915-9075 and later).
  • For these Threat IDs to protect against attacks for this vulnerability,

Official advisory · high-confidence parse· fetched 1 hour ago·verify at source

Discussion(0)

No comments yet. Share field notes, upgrade gotchas, or questions — verify against the vendor advisory before acting on community advice.

Sign in to join the discussion.