PAN-OS: Authentication Bypass in the Management Web Interface (PAN-SA-2024-0015)

Summary

CVECVE-2024-0012
StatePUBLISHED
Assignerpalo_alto
Source PriorityCVE Program / NVD first with legacy fallback
Published2024-11-18 16:15:11 UTC
Updated2026-08-04 05:16:29 UTC
DescriptionAn authentication bypass in Palo Alto Networks PAN-OS software enables an unauthenticated attacker with network access to the management web interface to gain PAN-OS administrator privileges to perform administrative actions, tamper with the configuration, or exploit other authenticated privilege escalation vulnerabilities like CVE-2024-9474 https://security.paloaltonetworks.com/CVE-2024-9474 . The risk of this issue is greatly reduced if you secure access to the management web interface by restricting access to only trusted internal IP addresses according to our recommended  best practice deployment guidelines https://live.paloaltonetworks.com/t5/community-blogs/tips-amp-tricks-how-to-secure-the-management-access-of-your-palo/ba-p/464431 . This issue is applicable only to PAN-OS 10.2, PAN-OS 11.0, PAN-OS 11.1, and PAN-OS 11.2 software. Cloud NGFW and Prisma Access are not impacted by this vulnerability.

Risk And Classification

Primary CVSS: v4.0 9.3 CRITICAL from [email protected]

CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:L/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:N/R:U/V:C/RE:H/U:Red

EPSS: 0.996980000 probability, percentile 0.999500000 (date 2026-08-05)

CISA KEV: Listed on 2024-11-18; due 2024-12-09; ransomware use Known

Problem Types: CWE-306 | CWE-306 CWE-306 Missing Authentication for Critical Function


VersionSourceTypeScoreSeverityVector
4.0[email protected]Secondary9.3CRITICALCVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:L/SI:N/SA:N/E:X/C...
4.0CNACVSS9.3CRITICALCVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:L/SI:N/SA:N/AU:N/...
4.0CNACVSS5.9MEDIUMCVSS:4.0/AV:N/AC:L/AT:P/PR:H/UI:N/VC:N/VI:H/VA:N/SC:N/SI:N/SA:N/AU:N/...
3.1[email protected]Primary9.8CRITICALCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

CVSS v4.0 Breakdown

Attack Vector
Network
Attack Complexity
Low
Attack Requirements
None
Privileges Required
None
User Interaction
None
Confidentiality
High
Integrity
High
Availability
High
Sub Conf.
Low
Sub Integrity
None
Sub Availability
None

CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:L/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:N/R:U/V:C/RE:H/U:Red

CVSS v3.1 Breakdown

Attack Vector
Network
Attack Complexity
Low
Privileges Required
None
User Interaction
None
Scope
Unchanged
Confidentiality
High
Integrity
High
Availability
High

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

CISA Known Exploited Vulnerability

VendorPalo Alto Networks
ProductPAN-OS
NamePalo Alto Networks PAN-OS Management Interface Authentication Bypass Vulnerability
Required ActionApply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable. Additionally, management interface for affected devices should not be exposed to untrusted networks, including the internet.
Noteshttps://security.paloaltonetworks.com/CVE-2024-0012 ; https://nvd.nist.gov/vuln/detail/CVE-2024-0012

NVD Known Affected Configurations (CPE 2.3)

TypeVendorProductVersionUpdateEditionLanguage
Operating System Paloaltonetworks Pan-os 10.2.0 - All All
Operating System Paloaltonetworks Pan-os 10.2.0 h1 All All
Operating System Paloaltonetworks Pan-os 10.2.0 h2 All All
Operating System Paloaltonetworks Pan-os 10.2.0 h3 All All
Operating System Paloaltonetworks Pan-os 10.2.1 - All All
Operating System Paloaltonetworks Pan-os 10.2.1 h1 All All
Operating System Paloaltonetworks Pan-os 10.2.1 h2 All All
Operating System Paloaltonetworks Pan-os 10.2.10 - All All
Operating System Paloaltonetworks Pan-os 10.2.10 h2 All All
Operating System Paloaltonetworks Pan-os 10.2.10 h3 All All
Operating System Paloaltonetworks Pan-os 10.2.10 h4 All All
Operating System Paloaltonetworks Pan-os 10.2.10 h5 All All
Operating System Paloaltonetworks Pan-os 10.2.10 h7 All All
Operating System Paloaltonetworks Pan-os 10.2.11 - All All
Operating System Paloaltonetworks Pan-os 10.2.11 h1 All All
Operating System Paloaltonetworks Pan-os 10.2.11 h2 All All
Operating System Paloaltonetworks Pan-os 10.2.11 h3 All All
Operating System Paloaltonetworks Pan-os 10.2.11 h4 All All
Operating System Paloaltonetworks Pan-os 10.2.12 - All All
Operating System Paloaltonetworks Pan-os 10.2.12 h1 All All
Operating System Paloaltonetworks Pan-os 10.2.2 - All All
Operating System Paloaltonetworks Pan-os 10.2.2 h1 All All
Operating System Paloaltonetworks Pan-os 10.2.2 h2 All All
Operating System Paloaltonetworks Pan-os 10.2.2 h4 All All
Operating System Paloaltonetworks Pan-os 10.2.2 h5 All All
Operating System Paloaltonetworks Pan-os 10.2.3 - All All
Operating System Paloaltonetworks Pan-os 10.2.3 h11 All All
Operating System Paloaltonetworks Pan-os 10.2.3 h12 All All
Operating System Paloaltonetworks Pan-os 10.2.3 h13 All All
Operating System Paloaltonetworks Pan-os 10.2.3 h2 All All
Operating System Paloaltonetworks Pan-os 10.2.3 h4 All All
Operating System Paloaltonetworks Pan-os 10.2.3 h9 All All
Operating System Paloaltonetworks Pan-os 10.2.4 - All All
Operating System Paloaltonetworks Pan-os 10.2.4 h10 All All
Operating System Paloaltonetworks Pan-os 10.2.4 h16 All All
Operating System Paloaltonetworks Pan-os 10.2.4 h2 All All
Operating System Paloaltonetworks Pan-os 10.2.4 h3 All All
Operating System Paloaltonetworks Pan-os 10.2.4 h4 All All
Operating System Paloaltonetworks Pan-os 10.2.5 - All All
Operating System Paloaltonetworks Pan-os 10.2.5 h1 All All
Operating System Paloaltonetworks Pan-os 10.2.5 h4 All All
Operating System Paloaltonetworks Pan-os 10.2.5 h6 All All
Operating System Paloaltonetworks Pan-os 10.2.6 - All All
Operating System Paloaltonetworks Pan-os 10.2.6 h1 All All
Operating System Paloaltonetworks Pan-os 10.2.6 h3 All All
Operating System Paloaltonetworks Pan-os 10.2.7 - All All
Operating System Paloaltonetworks Pan-os 10.2.7 h1 All All
Operating System Paloaltonetworks Pan-os 10.2.7 h12 All All
Operating System Paloaltonetworks Pan-os 10.2.7 h16 All All
Operating System Paloaltonetworks Pan-os 10.2.7 h3 All All
Operating System Paloaltonetworks Pan-os 10.2.7 h6 All All
Operating System Paloaltonetworks Pan-os 10.2.7 h8 All All
Operating System Paloaltonetworks Pan-os 10.2.8 - All All
Operating System Paloaltonetworks Pan-os 10.2.8 h10 All All
Operating System Paloaltonetworks Pan-os 10.2.8 h13 All All
Operating System Paloaltonetworks Pan-os 10.2.8 h3 All All
Operating System Paloaltonetworks Pan-os 10.2.8 h4 All All
Operating System Paloaltonetworks Pan-os 10.2.9 - All All
Operating System Paloaltonetworks Pan-os 10.2.9 h1 All All
Operating System Paloaltonetworks Pan-os 10.2.9 h11 All All
Operating System Paloaltonetworks Pan-os 10.2.9 h14 All All
Operating System Paloaltonetworks Pan-os 10.2.9 h9 All All
Operating System Paloaltonetworks Pan-os 11.0.0 - All All
Operating System Paloaltonetworks Pan-os 11.0.0 h1 All All
Operating System Paloaltonetworks Pan-os 11.0.0 h2 All All
Operating System Paloaltonetworks Pan-os 11.0.0 h3 All All
Operating System Paloaltonetworks Pan-os 11.0.1 - All All
Operating System Paloaltonetworks Pan-os 11.0.1 h2 All All
Operating System Paloaltonetworks Pan-os 11.0.1 h3 All All
Operating System Paloaltonetworks Pan-os 11.0.1 h4 All All
Operating System Paloaltonetworks Pan-os 11.0.2 - All All
Operating System Paloaltonetworks Pan-os 11.0.2 h1 All All
Operating System Paloaltonetworks Pan-os 11.0.2 h2 All All
Operating System Paloaltonetworks Pan-os 11.0.2 h3 All All
Operating System Paloaltonetworks Pan-os 11.0.2 h4 All All
Operating System Paloaltonetworks Pan-os 11.0.3 - All All
Operating System Paloaltonetworks Pan-os 11.0.3 h1 All All
Operating System Paloaltonetworks Pan-os 11.0.3 h10 All All
Operating System Paloaltonetworks Pan-os 11.0.3 h12 All All
Operating System Paloaltonetworks Pan-os 11.0.3 h3 All All
Operating System Paloaltonetworks Pan-os 11.0.3 h5 All All
Operating System Paloaltonetworks Pan-os 11.0.4 - All All
Operating System Paloaltonetworks Pan-os 11.0.4 h1 All All
Operating System Paloaltonetworks Pan-os 11.0.4 h2 All All
Operating System Paloaltonetworks Pan-os 11.0.4 h5 All All
Operating System Paloaltonetworks Pan-os 11.0.5 - All All
Operating System Paloaltonetworks Pan-os 11.0.5 h1 All All
Operating System Paloaltonetworks Pan-os 11.0.6 - All All
Operating System Paloaltonetworks Pan-os 11.1.0 - All All
Operating System Paloaltonetworks Pan-os 11.1.0 h1 All All
Operating System Paloaltonetworks Pan-os 11.1.0 h2 All All
Operating System Paloaltonetworks Pan-os 11.1.0 h3 All All
Operating System Paloaltonetworks Pan-os 11.1.1 - All All
Operating System Paloaltonetworks Pan-os 11.1.1 h1 All All
Operating System Paloaltonetworks Pan-os 11.1.2 - All All
Operating System Paloaltonetworks Pan-os 11.1.2 h1 All All
Operating System Paloaltonetworks Pan-os 11.1.2 h12 All All
Operating System Paloaltonetworks Pan-os 11.1.2 h14 All All
Operating System Paloaltonetworks Pan-os 11.1.2 h3 All All
Operating System Paloaltonetworks Pan-os 11.1.2 h4 All All
Operating System Paloaltonetworks Pan-os 11.1.2 h9 All All
Operating System Paloaltonetworks Pan-os 11.1.3 - All All
Operating System Paloaltonetworks Pan-os 11.1.3 h1 All All
Operating System Paloaltonetworks Pan-os 11.1.3 h10 All All
Operating System Paloaltonetworks Pan-os 11.1.3 h2 All All
Operating System Paloaltonetworks Pan-os 11.1.3 h4 All All
Operating System Paloaltonetworks Pan-os 11.1.3 h6 All All
Operating System Paloaltonetworks Pan-os 11.1.4 - All All
Operating System Paloaltonetworks Pan-os 11.1.4 h1 All All
Operating System Paloaltonetworks Pan-os 11.1.4 h4 All All
Operating System Paloaltonetworks Pan-os 11.1.5 - All All
Operating System Paloaltonetworks Pan-os 11.2.0 - All All
Operating System Paloaltonetworks Pan-os 11.2.1 - All All
Operating System Paloaltonetworks Pan-os 11.2.2 - All All
Operating System Paloaltonetworks Pan-os 11.2.2 h1 All All
Operating System Paloaltonetworks Pan-os 11.2.3 - All All
Operating System Paloaltonetworks Pan-os 11.2.4 - All All

Vendor Declared Affected Products

SourceVendorProductVersionPlatforms
CNA Palo Alto Networks Cloud NGFW unaffected All Not specified
CNA Palo Alto Networks PAN-OS affected 11.2.0 11.2.4-h1 custom Not specified
CNA Palo Alto Networks PAN-OS affected 11.1.0 11.1.5-h1 custom Not specified
CNA Palo Alto Networks PAN-OS affected 11.0.0 11.0.6-h1 custom Not specified
CNA Palo Alto Networks PAN-OS affected 10.2.0 10.2.12-h2 custom Not specified
CNA Palo Alto Networks PAN-OS unaffected 10.1.0 Not specified
CNA Palo Alto Networks Prisma Access unaffected All Not specified

References

ReferenceSourceLinkTags
www.cisa.gov/known-exploited-vulnerabilities-catalog 134c704f-9b21-4f2e-91b3-4a467353bcc0 www.cisa.gov US Government Resource
unit42.paloaltonetworks.com/cve-2024-0012-cve-2024-9474 af854a3a-2127-422b-91ae-364da2661108 unit42.paloaltonetworks.com Vendor Advisory
security.paloaltonetworks.com/CVE-2024-0012 [email protected] security.paloaltonetworks.com Vendor Advisory
labs.watchtowr.com/pots-and-pans-aka-an-sslvpn-palo-alto-pan-os-cve-2024-0012-an... 134c704f-9b21-4f2e-91b3-4a467353bcc0 labs.watchtowr.com Exploit, Third Party Advisory
CVE Program record CVE.ORG www.cve.org canonical
NVD vulnerability detail NVD nvd.nist.gov canonical, analysis
CISA Known Exploited Vulnerabilities catalog CISA www.cisa.gov kev

Vendor Comments And Credit

Discovery Credit

CNA: Palo Alto Networks thanks our Deep Product Security Research Team for discovering this issue internally from threat activity. (en)

Additional Advisory Data

SourceTimeEvent
CNA2024-11-18T14:20:00.000ZCVE-2024-0012 assigned to this publication as the vulnerability is identified and fixed
CNA2024-11-15T22:00:00.000ZAnswered a FAQ about indicators of compromise
CNA2024-11-14T22:18:00.000ZRaised the severity of PAN-SA-2024-0015 bulletin as we have observed threat activity
CNA2024-11-11T01:03:00.000ZAdded instructions to find your devices with an internet-facing management interface discovered in our scans
CNA2024-11-08T13:00:00.000ZInitially published as PAN-SA-2024-0015
ADP2024-11-18T00:00:00.000ZCVE-2024-0012 added to CISA KEV

Solutions

CNA: We strongly recommend that you secure access to your management interface following the instructions in the workarounds section below. This issue is fixed in PAN-OS 10.2.12-h2, PAN-OS 11.0.6-h1, PAN-OS 11.1.5-h1, PAN-OS 11.2.4-h1, and all later PAN-OS versions. In addition, in an attempt to provide the most seamless upgrade path for our customers, we are making fixes available for other TAC-preferred and commonly deployed maintenance releases. * Additional PAN-OS 11.2 fixes: * ​​11.2.0-h1 * 11.2.1-h1 * 11.2.2-h2 * 11.2.3-h3 * 11.2.4-h1 * Additional PAN-OS 11.1 fixes: * 11.1.0-h4 * 11.1.1-h2 * 11.1.2-h15 * 11.1.3-h11 * 11.1.4-h7 * 11.1.5-h1 * Additional PAN-OS 11.0 fixes: * 11.0.0-h4 * 11.0.1-h5 * 11.0.2-h5 * 11.0.3-h13 * 11.0.4-h6 * 11.0.5-h2 * 11.0.6-h1 * Additional PAN-OS 10.2 fixes: * 10.2.0-h4 * 10.2.1-h3 * 10.2.2-h6 * 10.2.3-h14 * 10.2.4-h32 * 10.2.5-h9 * 10.2.6-h6 * 10.2.7-h18 * 10.2.8-h15 * 10.2.9-h16 * 10.2.10-h9 * 10.2.11-h6 * 10.2.12-h2

Workarounds

CNA: Recommended mitigation—The vast majority of firewalls already follow Palo Alto Networks and industry best practices. However, if you haven’t already, we strongly recommend that you secure access to your management interface according to our best practice deployment guidelines. Specifically, you should restrict access to the management interface to only trusted internal IP addresses to prevent external access from the internet. Additionally, if you have a Threat Prevention subscription, you can block these attacks using Threat IDs 95746, 95747, 95752, 95753, 95759, and 95763 (available in Applications and Threats content version 8915-9075 and later). For these Threat IDs to protect against attacks for this vulnerability, * Ensure that all the listed Threat IDs are set to block mode, * Route incoming traffic for the MGT port through a DP port https://docs.paloaltonetworks.com/best-practices/10-1/administrative-access-best-practices/administrative-access-best-practices/deploy-administrative-access-best-practices#id59206398-3dab-4b2f-9b4b-7ea500d036ba , e.g., enabling management profile on a DP interface for management access, * Replace the Certificate for Inbound Traffic Management https://docs.paloaltonetworks.com/best-practices/10-1/administrative-access-best-practices/administrative-access-best-practices/deploy-administrative-access-best-practices#id112f7714-8995-4496-bbf9-781e63dec71c , * Decrypt inbound traffic to the management interface so the firewall can inspect it https://docs.paloaltonetworks.com/best-practices/10-1/administrative-access-best-practices/administrative-access-best-practices/deploy-administrative-access-best-practices#idbbd82587-17a2-42b4-9245-d3714e1e13a2 , and * Enable threat prevention on the inbound traffic to management services. Review information about how to secure management access to your Palo Alto Networks firewalls: * Palo Alto Networks LIVEcommunity article:  https://live.paloaltonetworks.com/t5/community-blogs/tips-amp-tricks-how-to-secure-the-management-access-of-your-palo/ba-p/464431 https://live.paloaltonetworks.com/t5/community-blogs/tips-amp-tricks-how-to-secure-the-management-access-of-your-palo/ba-p/464431 * Palo Alto Networks official and more detailed technical documentation:  https://docs.paloaltonetworks.com/best-practices/10-1/administrative-access-best-practices/administrative-access-best-practices/deploy-administrative-access-best-practices https://docs.paloaltonetworks.com/best-practices/10-1/administrative-access-best-practices/administrative-access-best-practices/deploy-administrative-access-best-practices

Exploits

CNA: Palo Alto Networks observed threat activity that exploits this vulnerability against a limited number of management web interfaces that are exposed to internet traffic coming from outside the network.

© CVE.report 2026

Use of this information constitutes acceptance for use in an AS IS condition. There are NO warranties, implied or otherwise, with regard to this information or its use. Any use of this information is at the user's risk. It is the responsibility of user to evaluate the accuracy, completeness or usefulness of any information, opinion, advice or other content. EACH USER WILL BE SOLELY RESPONSIBLE FOR ANY consequences of his or her direct or indirect use of this web site. ALL WARRANTIES OF ANY KIND ARE EXPRESSLY DISCLAIMED. This site will NOT BE LIABLE FOR ANY DIRECT, INDIRECT or any other kind of loss.

CVE, CWE, and OVAL are registred trademarks of The MITRE Corporation and the authoritative source of CVE content is MITRE's CVE web site. This site includes MITRE data granted under the following license.

Free CVE JSON API cve.report/api

CVE.report and Source URL Uptime Status status.cve.report