PAN-OS: Authentication Bypass in the Management Web Interface (PAN-SA-2024-0015)
Summary
| CVE | CVE-2024-0012 |
|---|---|
| State | PUBLISHED |
| Assigner | palo_alto |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2024-11-18 16:15:11 UTC |
| Updated | 2026-08-04 05:16:29 UTC |
| Description | An authentication bypass in Palo Alto Networks PAN-OS software enables an unauthenticated attacker with network access to the management web interface to gain PAN-OS administrator privileges to perform administrative actions, tamper with the configuration, or exploit other authenticated privilege escalation vulnerabilities like CVE-2024-9474 https://security.paloaltonetworks.com/CVE-2024-9474 . The risk of this issue is greatly reduced if you secure access to the management web interface by restricting access to only trusted internal IP addresses according to our recommended best practice deployment guidelines https://live.paloaltonetworks.com/t5/community-blogs/tips-amp-tricks-how-to-secure-the-management-access-of-your-palo/ba-p/464431 . This issue is applicable only to PAN-OS 10.2, PAN-OS 11.0, PAN-OS 11.1, and PAN-OS 11.2 software. Cloud NGFW and Prisma Access are not impacted by this vulnerability. |
Risk And Classification
Primary CVSS: v4.0 9.3 CRITICAL from [email protected]
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:L/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:N/R:U/V:C/RE:H/U:Red
EPSS: 0.996980000 probability, percentile 0.999500000 (date 2026-08-05)
CISA KEV: Listed on 2024-11-18; due 2024-12-09; ransomware use Known
Problem Types: CWE-306 | CWE-306 CWE-306 Missing Authentication for Critical Function
| Version | Source | Type | Score | Severity | Vector |
|---|---|---|---|---|---|
| 4.0 | [email protected] | Secondary | 9.3 | CRITICAL | CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:L/SI:N/SA:N/E:X/C... |
| 4.0 | CNA | CVSS | 9.3 | CRITICAL | CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:L/SI:N/SA:N/AU:N/... |
| 4.0 | CNA | CVSS | 5.9 | MEDIUM | CVSS:4.0/AV:N/AC:L/AT:P/PR:H/UI:N/VC:N/VI:H/VA:N/SC:N/SI:N/SA:N/AU:N/... |
| 3.1 | [email protected] | Primary | 9.8 | CRITICAL | CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H |
CVSS v4.0 Breakdown
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:L/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:N/R:U/V:C/RE:H/U:Red
CVSS v3.1 Breakdown
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
CISA Known Exploited Vulnerability
| Vendor | Palo Alto Networks |
|---|---|
| Product | PAN-OS |
| Name | Palo Alto Networks PAN-OS Management Interface Authentication Bypass Vulnerability |
| Required Action | Apply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable. Additionally, management interface for affected devices should not be exposed to untrusted networks, including the internet. |
| Notes | https://security.paloaltonetworks.com/CVE-2024-0012 ; https://nvd.nist.gov/vuln/detail/CVE-2024-0012 |
NVD Known Affected Configurations (CPE 2.3)
| Type | Vendor | Product | Version | Update | Edition | Language |
|---|---|---|---|---|---|---|
| Operating System | Paloaltonetworks | Pan-os | 10.2.0 | - | All | All |
| Operating System | Paloaltonetworks | Pan-os | 10.2.0 | h1 | All | All |
| Operating System | Paloaltonetworks | Pan-os | 10.2.0 | h2 | All | All |
| Operating System | Paloaltonetworks | Pan-os | 10.2.0 | h3 | All | All |
| Operating System | Paloaltonetworks | Pan-os | 10.2.1 | - | All | All |
| Operating System | Paloaltonetworks | Pan-os | 10.2.1 | h1 | All | All |
| Operating System | Paloaltonetworks | Pan-os | 10.2.1 | h2 | All | All |
| Operating System | Paloaltonetworks | Pan-os | 10.2.10 | - | All | All |
| Operating System | Paloaltonetworks | Pan-os | 10.2.10 | h2 | All | All |
| Operating System | Paloaltonetworks | Pan-os | 10.2.10 | h3 | All | All |
| Operating System | Paloaltonetworks | Pan-os | 10.2.10 | h4 | All | All |
| Operating System | Paloaltonetworks | Pan-os | 10.2.10 | h5 | All | All |
| Operating System | Paloaltonetworks | Pan-os | 10.2.10 | h7 | All | All |
| Operating System | Paloaltonetworks | Pan-os | 10.2.11 | - | All | All |
| Operating System | Paloaltonetworks | Pan-os | 10.2.11 | h1 | All | All |
| Operating System | Paloaltonetworks | Pan-os | 10.2.11 | h2 | All | All |
| Operating System | Paloaltonetworks | Pan-os | 10.2.11 | h3 | All | All |
| Operating System | Paloaltonetworks | Pan-os | 10.2.11 | h4 | All | All |
| Operating System | Paloaltonetworks | Pan-os | 10.2.12 | - | All | All |
| Operating System | Paloaltonetworks | Pan-os | 10.2.12 | h1 | All | All |
| Operating System | Paloaltonetworks | Pan-os | 10.2.2 | - | All | All |
| Operating System | Paloaltonetworks | Pan-os | 10.2.2 | h1 | All | All |
| Operating System | Paloaltonetworks | Pan-os | 10.2.2 | h2 | All | All |
| Operating System | Paloaltonetworks | Pan-os | 10.2.2 | h4 | All | All |
| Operating System | Paloaltonetworks | Pan-os | 10.2.2 | h5 | All | All |
| Operating System | Paloaltonetworks | Pan-os | 10.2.3 | - | All | All |
| Operating System | Paloaltonetworks | Pan-os | 10.2.3 | h11 | All | All |
| Operating System | Paloaltonetworks | Pan-os | 10.2.3 | h12 | All | All |
| Operating System | Paloaltonetworks | Pan-os | 10.2.3 | h13 | All | All |
| Operating System | Paloaltonetworks | Pan-os | 10.2.3 | h2 | All | All |
| Operating System | Paloaltonetworks | Pan-os | 10.2.3 | h4 | All | All |
| Operating System | Paloaltonetworks | Pan-os | 10.2.3 | h9 | All | All |
| Operating System | Paloaltonetworks | Pan-os | 10.2.4 | - | All | All |
| Operating System | Paloaltonetworks | Pan-os | 10.2.4 | h10 | All | All |
| Operating System | Paloaltonetworks | Pan-os | 10.2.4 | h16 | All | All |
| Operating System | Paloaltonetworks | Pan-os | 10.2.4 | h2 | All | All |
| Operating System | Paloaltonetworks | Pan-os | 10.2.4 | h3 | All | All |
| Operating System | Paloaltonetworks | Pan-os | 10.2.4 | h4 | All | All |
| Operating System | Paloaltonetworks | Pan-os | 10.2.5 | - | All | All |
| Operating System | Paloaltonetworks | Pan-os | 10.2.5 | h1 | All | All |
| Operating System | Paloaltonetworks | Pan-os | 10.2.5 | h4 | All | All |
| Operating System | Paloaltonetworks | Pan-os | 10.2.5 | h6 | All | All |
| Operating System | Paloaltonetworks | Pan-os | 10.2.6 | - | All | All |
| Operating System | Paloaltonetworks | Pan-os | 10.2.6 | h1 | All | All |
| Operating System | Paloaltonetworks | Pan-os | 10.2.6 | h3 | All | All |
| Operating System | Paloaltonetworks | Pan-os | 10.2.7 | - | All | All |
| Operating System | Paloaltonetworks | Pan-os | 10.2.7 | h1 | All | All |
| Operating System | Paloaltonetworks | Pan-os | 10.2.7 | h12 | All | All |
| Operating System | Paloaltonetworks | Pan-os | 10.2.7 | h16 | All | All |
| Operating System | Paloaltonetworks | Pan-os | 10.2.7 | h3 | All | All |
| Operating System | Paloaltonetworks | Pan-os | 10.2.7 | h6 | All | All |
| Operating System | Paloaltonetworks | Pan-os | 10.2.7 | h8 | All | All |
| Operating System | Paloaltonetworks | Pan-os | 10.2.8 | - | All | All |
| Operating System | Paloaltonetworks | Pan-os | 10.2.8 | h10 | All | All |
| Operating System | Paloaltonetworks | Pan-os | 10.2.8 | h13 | All | All |
| Operating System | Paloaltonetworks | Pan-os | 10.2.8 | h3 | All | All |
| Operating System | Paloaltonetworks | Pan-os | 10.2.8 | h4 | All | All |
| Operating System | Paloaltonetworks | Pan-os | 10.2.9 | - | All | All |
| Operating System | Paloaltonetworks | Pan-os | 10.2.9 | h1 | All | All |
| Operating System | Paloaltonetworks | Pan-os | 10.2.9 | h11 | All | All |
| Operating System | Paloaltonetworks | Pan-os | 10.2.9 | h14 | All | All |
| Operating System | Paloaltonetworks | Pan-os | 10.2.9 | h9 | All | All |
| Operating System | Paloaltonetworks | Pan-os | 11.0.0 | - | All | All |
| Operating System | Paloaltonetworks | Pan-os | 11.0.0 | h1 | All | All |
| Operating System | Paloaltonetworks | Pan-os | 11.0.0 | h2 | All | All |
| Operating System | Paloaltonetworks | Pan-os | 11.0.0 | h3 | All | All |
| Operating System | Paloaltonetworks | Pan-os | 11.0.1 | - | All | All |
| Operating System | Paloaltonetworks | Pan-os | 11.0.1 | h2 | All | All |
| Operating System | Paloaltonetworks | Pan-os | 11.0.1 | h3 | All | All |
| Operating System | Paloaltonetworks | Pan-os | 11.0.1 | h4 | All | All |
| Operating System | Paloaltonetworks | Pan-os | 11.0.2 | - | All | All |
| Operating System | Paloaltonetworks | Pan-os | 11.0.2 | h1 | All | All |
| Operating System | Paloaltonetworks | Pan-os | 11.0.2 | h2 | All | All |
| Operating System | Paloaltonetworks | Pan-os | 11.0.2 | h3 | All | All |
| Operating System | Paloaltonetworks | Pan-os | 11.0.2 | h4 | All | All |
| Operating System | Paloaltonetworks | Pan-os | 11.0.3 | - | All | All |
| Operating System | Paloaltonetworks | Pan-os | 11.0.3 | h1 | All | All |
| Operating System | Paloaltonetworks | Pan-os | 11.0.3 | h10 | All | All |
| Operating System | Paloaltonetworks | Pan-os | 11.0.3 | h12 | All | All |
| Operating System | Paloaltonetworks | Pan-os | 11.0.3 | h3 | All | All |
| Operating System | Paloaltonetworks | Pan-os | 11.0.3 | h5 | All | All |
| Operating System | Paloaltonetworks | Pan-os | 11.0.4 | - | All | All |
| Operating System | Paloaltonetworks | Pan-os | 11.0.4 | h1 | All | All |
| Operating System | Paloaltonetworks | Pan-os | 11.0.4 | h2 | All | All |
| Operating System | Paloaltonetworks | Pan-os | 11.0.4 | h5 | All | All |
| Operating System | Paloaltonetworks | Pan-os | 11.0.5 | - | All | All |
| Operating System | Paloaltonetworks | Pan-os | 11.0.5 | h1 | All | All |
| Operating System | Paloaltonetworks | Pan-os | 11.0.6 | - | All | All |
| Operating System | Paloaltonetworks | Pan-os | 11.1.0 | - | All | All |
| Operating System | Paloaltonetworks | Pan-os | 11.1.0 | h1 | All | All |
| Operating System | Paloaltonetworks | Pan-os | 11.1.0 | h2 | All | All |
| Operating System | Paloaltonetworks | Pan-os | 11.1.0 | h3 | All | All |
| Operating System | Paloaltonetworks | Pan-os | 11.1.1 | - | All | All |
| Operating System | Paloaltonetworks | Pan-os | 11.1.1 | h1 | All | All |
| Operating System | Paloaltonetworks | Pan-os | 11.1.2 | - | All | All |
| Operating System | Paloaltonetworks | Pan-os | 11.1.2 | h1 | All | All |
| Operating System | Paloaltonetworks | Pan-os | 11.1.2 | h12 | All | All |
| Operating System | Paloaltonetworks | Pan-os | 11.1.2 | h14 | All | All |
| Operating System | Paloaltonetworks | Pan-os | 11.1.2 | h3 | All | All |
| Operating System | Paloaltonetworks | Pan-os | 11.1.2 | h4 | All | All |
| Operating System | Paloaltonetworks | Pan-os | 11.1.2 | h9 | All | All |
| Operating System | Paloaltonetworks | Pan-os | 11.1.3 | - | All | All |
| Operating System | Paloaltonetworks | Pan-os | 11.1.3 | h1 | All | All |
| Operating System | Paloaltonetworks | Pan-os | 11.1.3 | h10 | All | All |
| Operating System | Paloaltonetworks | Pan-os | 11.1.3 | h2 | All | All |
| Operating System | Paloaltonetworks | Pan-os | 11.1.3 | h4 | All | All |
| Operating System | Paloaltonetworks | Pan-os | 11.1.3 | h6 | All | All |
| Operating System | Paloaltonetworks | Pan-os | 11.1.4 | - | All | All |
| Operating System | Paloaltonetworks | Pan-os | 11.1.4 | h1 | All | All |
| Operating System | Paloaltonetworks | Pan-os | 11.1.4 | h4 | All | All |
| Operating System | Paloaltonetworks | Pan-os | 11.1.5 | - | All | All |
| Operating System | Paloaltonetworks | Pan-os | 11.2.0 | - | All | All |
| Operating System | Paloaltonetworks | Pan-os | 11.2.1 | - | All | All |
| Operating System | Paloaltonetworks | Pan-os | 11.2.2 | - | All | All |
| Operating System | Paloaltonetworks | Pan-os | 11.2.2 | h1 | All | All |
| Operating System | Paloaltonetworks | Pan-os | 11.2.3 | - | All | All |
| Operating System | Paloaltonetworks | Pan-os | 11.2.4 | - | All | All |
Vendor Declared Affected Products
| Source | Vendor | Product | Version | Platforms |
|---|---|---|---|---|
| CNA | Palo Alto Networks | Cloud NGFW | unaffected All | Not specified |
| CNA | Palo Alto Networks | PAN-OS | affected 11.2.0 11.2.4-h1 custom | Not specified |
| CNA | Palo Alto Networks | PAN-OS | affected 11.1.0 11.1.5-h1 custom | Not specified |
| CNA | Palo Alto Networks | PAN-OS | affected 11.0.0 11.0.6-h1 custom | Not specified |
| CNA | Palo Alto Networks | PAN-OS | affected 10.2.0 10.2.12-h2 custom | Not specified |
| CNA | Palo Alto Networks | PAN-OS | unaffected 10.1.0 | Not specified |
| CNA | Palo Alto Networks | Prisma Access | unaffected All | Not specified |
References
| Reference | Source | Link | Tags |
|---|---|---|---|
| www.cisa.gov/known-exploited-vulnerabilities-catalog | 134c704f-9b21-4f2e-91b3-4a467353bcc0 | www.cisa.gov | US Government Resource |
| unit42.paloaltonetworks.com/cve-2024-0012-cve-2024-9474 | af854a3a-2127-422b-91ae-364da2661108 | unit42.paloaltonetworks.com | Vendor Advisory |
| security.paloaltonetworks.com/CVE-2024-0012 | [email protected] | security.paloaltonetworks.com | Vendor Advisory |
| labs.watchtowr.com/pots-and-pans-aka-an-sslvpn-palo-alto-pan-os-cve-2024-0012-an... | 134c704f-9b21-4f2e-91b3-4a467353bcc0 | labs.watchtowr.com | Exploit, Third Party Advisory |
| CVE Program record | CVE.ORG | www.cve.org | canonical |
| NVD vulnerability detail | NVD | nvd.nist.gov | canonical, analysis |
| CISA Known Exploited Vulnerabilities catalog | CISA | www.cisa.gov | kev |
Vendor Comments And Credit
Discovery Credit
CNA: Palo Alto Networks thanks our Deep Product Security Research Team for discovering this issue internally from threat activity. (en)
Additional Advisory Data
| Source | Time | Event |
|---|---|---|
| CNA | 2024-11-18T14:20:00.000Z | CVE-2024-0012 assigned to this publication as the vulnerability is identified and fixed |
| CNA | 2024-11-15T22:00:00.000Z | Answered a FAQ about indicators of compromise |
| CNA | 2024-11-14T22:18:00.000Z | Raised the severity of PAN-SA-2024-0015 bulletin as we have observed threat activity |
| CNA | 2024-11-11T01:03:00.000Z | Added instructions to find your devices with an internet-facing management interface discovered in our scans |
| CNA | 2024-11-08T13:00:00.000Z | Initially published as PAN-SA-2024-0015 |
| ADP | 2024-11-18T00:00:00.000Z | CVE-2024-0012 added to CISA KEV |
Solutions
CNA: We strongly recommend that you secure access to your management interface following the instructions in the workarounds section below. This issue is fixed in PAN-OS 10.2.12-h2, PAN-OS 11.0.6-h1, PAN-OS 11.1.5-h1, PAN-OS 11.2.4-h1, and all later PAN-OS versions. In addition, in an attempt to provide the most seamless upgrade path for our customers, we are making fixes available for other TAC-preferred and commonly deployed maintenance releases. * Additional PAN-OS 11.2 fixes: * 11.2.0-h1 * 11.2.1-h1 * 11.2.2-h2 * 11.2.3-h3 * 11.2.4-h1 * Additional PAN-OS 11.1 fixes: * 11.1.0-h4 * 11.1.1-h2 * 11.1.2-h15 * 11.1.3-h11 * 11.1.4-h7 * 11.1.5-h1 * Additional PAN-OS 11.0 fixes: * 11.0.0-h4 * 11.0.1-h5 * 11.0.2-h5 * 11.0.3-h13 * 11.0.4-h6 * 11.0.5-h2 * 11.0.6-h1 * Additional PAN-OS 10.2 fixes: * 10.2.0-h4 * 10.2.1-h3 * 10.2.2-h6 * 10.2.3-h14 * 10.2.4-h32 * 10.2.5-h9 * 10.2.6-h6 * 10.2.7-h18 * 10.2.8-h15 * 10.2.9-h16 * 10.2.10-h9 * 10.2.11-h6 * 10.2.12-h2
Workarounds
CNA: Recommended mitigation—The vast majority of firewalls already follow Palo Alto Networks and industry best practices. However, if you haven’t already, we strongly recommend that you secure access to your management interface according to our best practice deployment guidelines. Specifically, you should restrict access to the management interface to only trusted internal IP addresses to prevent external access from the internet. Additionally, if you have a Threat Prevention subscription, you can block these attacks using Threat IDs 95746, 95747, 95752, 95753, 95759, and 95763 (available in Applications and Threats content version 8915-9075 and later). For these Threat IDs to protect against attacks for this vulnerability, * Ensure that all the listed Threat IDs are set to block mode, * Route incoming traffic for the MGT port through a DP port https://docs.paloaltonetworks.com/best-practices/10-1/administrative-access-best-practices/administrative-access-best-practices/deploy-administrative-access-best-practices#id59206398-3dab-4b2f-9b4b-7ea500d036ba , e.g., enabling management profile on a DP interface for management access, * Replace the Certificate for Inbound Traffic Management https://docs.paloaltonetworks.com/best-practices/10-1/administrative-access-best-practices/administrative-access-best-practices/deploy-administrative-access-best-practices#id112f7714-8995-4496-bbf9-781e63dec71c , * Decrypt inbound traffic to the management interface so the firewall can inspect it https://docs.paloaltonetworks.com/best-practices/10-1/administrative-access-best-practices/administrative-access-best-practices/deploy-administrative-access-best-practices#idbbd82587-17a2-42b4-9245-d3714e1e13a2 , and * Enable threat prevention on the inbound traffic to management services. Review information about how to secure management access to your Palo Alto Networks firewalls: * Palo Alto Networks LIVEcommunity article: https://live.paloaltonetworks.com/t5/community-blogs/tips-amp-tricks-how-to-secure-the-management-access-of-your-palo/ba-p/464431 https://live.paloaltonetworks.com/t5/community-blogs/tips-amp-tricks-how-to-secure-the-management-access-of-your-palo/ba-p/464431 * Palo Alto Networks official and more detailed technical documentation: https://docs.paloaltonetworks.com/best-practices/10-1/administrative-access-best-practices/administrative-access-best-practices/deploy-administrative-access-best-practices https://docs.paloaltonetworks.com/best-practices/10-1/administrative-access-best-practices/administrative-access-best-practices/deploy-administrative-access-best-practices
Exploits
CNA: Palo Alto Networks observed threat activity that exploits this vulnerability against a limited number of management web interfaces that are exposed to internet traffic coming from outside the network.