CVE-2024-0012
Last modified
CVE-2024-0012 is a critical-severity vulnerability rated 9.8/10 on the CVSS scale. An authentication bypass in Palo Alto Networks PAN-OS software enables an unauthenticated attacker with network access to the management web interface to gain PAN-OS administrator privileges to perform administrative actions, tamper with the configuration, or exploit other authenticated privilege escalation vulnerabilities like CVE-2024-9474 https://security.paloaltonetworks.com/CVE-2024-9474 . The risk of this issue is greatly reduced if you secure access to the management web interface by restricting access to only trusted internal IP addresses according to our recommended best practice deployment guidelines https://live.paloaltonetworks.com/t5/community-blogs/tips-amp-tricks-how-to-secure-the-management-access-of-your-palo/ba-p/464431 . This issue is applicable only to PAN-OS 10.2, PAN-OS 11.0, PAN-OS 11.1, and PAN-OS 11.2 software. Cloud NGFW and Prisma Access are not impacted by this vulnerability.. CISA has confirmed active exploitation in the wild. EPSS estimates a 99.70% chance of exploitation in the next 30 days.
Description
An authentication bypass in Palo Alto Networks PAN-OS software enables an unauthenticated attacker with network access to the management web interface to gain PAN-OS administrator privileges to perform administrative actions, tamper with the configuration, or exploit other authenticated privilege escalation vulnerabilities like CVE-2024-9474 https://security.paloaltonetworks.com/CVE-2024-9474 . The risk of this issue is greatly reduced if you secure access to the management web interface by restricting access to only trusted internal IP addresses according to our recommended best practice deployment guidelines https://live.paloaltonetworks.com/t5/community-blogs/tips-amp-tricks-how-to-secure-the-management-access-of-your-palo/ba-p/464431 . This issue is applicable only to PAN-OS 10.2, PAN-OS 11.0, PAN-OS 11.1, and PAN-OS 11.2 software. Cloud NGFW and Prisma Access are not impacted by this vulnerability.
Metrics
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:L/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:N/R:U/V:C/RE:H/U:Red
Exploitation Status
This vulnerability is listed in CISA’s Known Exploited Vulnerabilities catalog, confirming active exploitation in the wild. Federal agencies must remediate by .
Weakness Enumeration
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Paloaltonetworks | Pan-Os | 10.2.0 |
| Paloaltonetworks | Pan-Os | 10.2.1 |
| Paloaltonetworks | Pan-Os | 10.2.2 |
| Paloaltonetworks | Pan-Os | 10.2.3 |
| Paloaltonetworks | Pan-Os | 10.2.4 |
| Paloaltonetworks | Pan-Os | 10.2.5 |
| Paloaltonetworks | Pan-Os | 10.2.6 |
| Paloaltonetworks | Pan-Os | 10.2.7 |
| Paloaltonetworks | Pan-Os | 10.2.8 |
| Paloaltonetworks | Pan-Os | 10.2.9 |
| Paloaltonetworks | Pan-Os | 10.2.10 |
| Paloaltonetworks | Pan-Os | 10.2.11 |
| Paloaltonetworks | Pan-Os | 10.2.12 |
| Paloaltonetworks | Pan-Os | 11.0.0 |
| Paloaltonetworks | Pan-Os | 11.0.1 |
| Paloaltonetworks | Pan-Os | 11.0.2 |
| Paloaltonetworks | Pan-Os | 11.0.3 |
| Paloaltonetworks | Pan-Os | 11.0.4 |
| Paloaltonetworks | Pan-Os | 11.0.5 |
| Paloaltonetworks | Pan-Os | 11.0.6 |
| Paloaltonetworks | Pan-Os | 11.1.0 |
| Paloaltonetworks | Pan-Os | 11.1.1 |
| Paloaltonetworks | Pan-Os | 11.1.2 |
| Paloaltonetworks | Pan-Os | 11.1.3 |
| Paloaltonetworks | Pan-Os | 11.1.4 |
| Paloaltonetworks | Pan-Os | 11.1.5 |
| Paloaltonetworks | Pan-Os | 11.2.0 |
| Paloaltonetworks | Pan-Os | 11.2.1 |
| Paloaltonetworks | Pan-Os | 11.2.2 |
| Paloaltonetworks | Pan-Os | 11.2.3 |
| Paloaltonetworks | Pan-Os | 11.2.4 |
References
- https://security.paloaltonetworks.com/CVE-2024-0012Vendor Advisory
- https://labs.watchtowr.com/pots-and-pans-aka-an-sslvpn-palo-alto-pan-os-cve-2024-0012-and-cve-2024-9474/Exploit, Third Party Advisory
- https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2024-0012US Government Resource
Timeline
- Published
- Last Modified
- Status
- Analyzed
Frequently Asked Questions
What is CVE-2024-0012?
How severe is CVE-2024-0012?
How do I fix CVE-2024-0012?
How Strix Helps
- How Strix found a critical auth bypass in etcdStrix autonomously discovered a critical authentication bypass in etcd, later designated CVE-2026-33413.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2024
- CVE-2024-0006Information exposure in the logging system in Yugabyte Platf…5.4
- CVE-2024-0007A cross-site scripting (XSS) vulnerability in Palo Alto Netw…4.8
- CVE-2024-0008Web sessions in the management interface in Palo Alto Networ…8.8
- CVE-2024-0009An improper verification vulnerability in the GlobalProtect …6.3
- CVE-2024-0010A reflected cross-site scripting (XSS) vulnerability in the …6.1
- CVE-2024-0011A reflected cross-site scripting (XSS) vulnerability in the …6.1
- CVE-2024-0014In startInstall of UpdateFetcher.java, there is a possible w…7.8
- CVE-2024-0015In convertToComponentName of DreamService.java, there is a p…7.8
- CVE-2024-0016In multiple locations, there is a possible out of bounds rea…5.3
- CVE-2024-0017In shouldUseNoOpLocation of CameraActivity.java, there is a …5.5
- CVE-2024-0018In convertYUV420Planar16ToY410 of ColorConverter.cpp, there …7.8
- CVE-2024-0019In setListening of AppOpsControllerImpl.java, there is a pos…5
Are you affected by CVE-2024-0012?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
