Executive brief
An authentication bypass vulnerability in the Palo Alto Networks PAN-OS management web interface allows unauthenticated remote attackers to gain administrator privileges. Attackers can perform administrative actions, modify configurations, or chain this with other vulnerabilities for further privilege escalation.
Affected products
- Palo Alto Networks PAN-OS 10.2, 11.0, 11.1, 11.2
Timeline
- 2024-11-18: disclosed
- 2024-11-18: kev added: Added to CISA Known Exploited Vulnerabilities Catalog
- 2024-11-18: exploited: Reported as exploited in the wild at time of publication.