LiveBreach Intelligence: data breaches, leaks & ransomware, tracked as they surfaceOngoing protection: GalaxyWarden →
Recent BreachesData breach tracker

CVE-2024-0012: Palo Alto Networks PAN-OS Management Interface Authentication Bypass Vulnerability

RBRecent Breaches Vulnerability Intelligence·Nov 18, 2024
Critical⚠ Actively exploited (CISA KEV)Ransomware-linked
Critical
Severity
Active
CISA KEV
Yes
Ransomware use
Dec 9, 2024
Patch deadline
⚠ Exploited in the wild. CISA added CVE-2024-0012 to its Known Exploited Vulnerabilities catalog on Nov 18, 2024, with a federal patch deadline of Dec 9, 2024 — meaning attackers are actively using it. If you run the affected software, patch it immediately. Ransomware crews are known to exploit this flaw.

Palo Alto Networks PAN-OS contains an authentication bypass vulnerability in the web-based management interface for several PAN-OS products, including firewalls and VPN concentrators.

CVE-2024-0012 is an authentication bypass vulnerability in the web-based management interface of Palo Alto Networks PAN-OS. It affects several PAN-OS products, including firewalls and VPN concentrators. Because the flaw allows unauthenticated access to a critical management surface, successful exploitation can give an attacker control of the device configuration and traffic policies. CISA notes known ransomware use of this vulnerability, which elevates the urgency for any organization running exposed or unpatched PAN-OS management interfaces.

How it works

The underlying weakness is CWE-306: Missing Authentication for Critical Function. In this case the critical function is the PAN-OS web-based management interface. An attacker who can reach that interface can bypass the normal authentication checks that should gate administrative actions. Once past authentication, the attacker can perform the same operations a legitimate administrator would—viewing or changing security policies, creating accounts, or altering network routing. Exact request sequences or payloads are not detailed in public summaries; defenders must treat any unauthenticated access to the management plane as a potential exploitation attempt and confirm technical details against the vendor advisory.

Am I affected? How to find it in your systems

PAN-OS is the operating system that runs on Palo Alto Networks next-generation firewalls and related appliances such as VPN concentrators. These devices commonly sit at network perimeters, data-center edges, or remote-access gateways. Inventory every Palo Alto Networks firewall or concentrator in your environment, then determine which of them have the web management interface enabled and reachable.

Because specific vulnerable version ranges are not listed here, compare every installed PAN-OS release against the official Palo Alto Networks advisory for CVE-2024-0012.

How to remediate

The primary remediation is to apply the vendor-supplied update that addresses CVE-2024-0012. Follow Palo Alto Networks’ published instructions for the exact software release that contains the fix. After patching, verify that the management interface still requires authentication and that no residual unauthenticated endpoints remain.

CISA’s required action is to apply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable; also ensure the management interface is never exposed to untrusted networks, including the internet.

If you can't patch immediately

Until the vendor update can be installed, reduce the attack surface with compensating controls that limit reachability and increase detection.

If your data may have been exposed

Actively exploited vulnerabilities that have been used by ransomware operators frequently lead to broader network compromise and data theft. If logs or other indicators suggest that an unauthenticated actor reached the management interface, treat the incident as a potential breach: isolate the device, preserve forensic evidence, and begin credential and configuration reviews. As an additional check, you can run a free exposure scan of your email addresses against known breach data sets to determine whether any of your accounts already appear in public leak collections.

AICompiled with AI assistance from public sources and published under our editorial standards.

Details

AffectedPalo Alto Networks · PAN-OS
WeaknessCWE-306
Added to CISA KEVNov 18, 2024
Federal patch deadlineDec 9, 2024
Known ransomware useYes
Check if your data is exposed →

Official records: NVD · CISA KEV

← All actively-exploited vulnerabilities