Junglewise Threat Intelligence

CVE-2024-0012: Palo Alto Networks PAN-OS Management Interface Authentication Bypass Vulnerability

CVE-2024-0012 · Severity: critical · CVSS 9.8 · Exploited in the wild · Published 2024-11-18

Technologies: Palo Alto Networks PAN-OS. Vendors: Palo Alto Networks, Palo Alto Networks.

Executive brief

An authentication bypass vulnerability in the Palo Alto Networks PAN-OS management web interface allows unauthenticated remote attackers to gain administrator privileges. Attackers can perform administrative actions, modify configurations, or chain this with other vulnerabilities for further privilege escalation.

Affected products

  • Palo Alto Networks PAN-OS 10.2, 11.0, 11.1, 11.2

Timeline

  • 2024-11-18: disclosed
  • 2024-11-18: kev added: Added to CISA Known Exploited Vulnerabilities Catalog
  • 2024-11-18: exploited: Reported as exploited in the wild at time of publication.

Related threats