CVE-2024-0012Critical· 9.8▾ Hadal⚠ Exploited in the wild0dayPoC availableAn authentication bypass in Palo Alto Networks PAN-OS software enables an unauthenticated attacker with network access to the management web interface to gain PAN-OS administrator privileges to perform administrative actions, tamper with…
▾ Hadal zone — Critical and actively exploited (CISA KEV / 0day)
impact 53.9 · likelihood 19.9 · exploitation 25 · ransomware 5
A public proof-of-concept already exists for this vulnerability — see Exploit availability below.
Public exploit / PoC code seen in 3 sources. Availability, not in-the-wild use.
Exploit-prediction probability, daily snapshots since Aug 4.
Disclosure to exploitation, from the record and what we observed since indexing it.
Disclosed via NVD
Federal remediation due Dec 9, 2024
Last analysed / modified upstream
100%
100% → 100%
11 GitHub repos · Metasploit ×1 · Nuclei ×1
Added to the CISA catalog on Nov 18, 2024. Federal remediation due Dec 9, 2024. View catalog ↗
An authentication bypass in Palo Alto Networks PAN-OS software enables an unauthenticated attacker with network access to the management web interface to gain PAN-OS administrator privileges to perform administrative actions, tamper with the configuration, or exploit other authenticated privilege escalation vulnerabilities like CVE-2024-9474 https://security.paloaltonetworks.com/CVE-2024-9474 .
The risk of this issue is greatly reduced if you secure access to the management web interface by restricting access to only trusted internal IP addresses according to our recommended best practice deployment guidelines https://live.paloaltonetworks.com/t5/community-blogs/tips-amp-tricks-how-to-secure-the-management-access-of-your-palo/ba-p/464431 .
This issue is applicable only to PAN-OS 10.2, PAN-OS 11.0, PAN-OS 11.1, and PAN-OS 11.2 software.
Cloud NGFW and Prisma Access are not impacted by this vulnerability.
pan-os = 10.2.0pan-os = 10.2.1pan-os = 10.2.2pan-os = 10.2.3pan-os = 10.2.4pan-os = 10.2.5pan-os = 10.2.6pan-os = 10.2.7pan-os = 10.2.8pan-os = 10.2.9pan-os = 10.2.10pan-os = 10.2.11pan-os = 10.2.12pan-os = 11.0.0pan-os = 11.0.1pan-os = 11.0.2pan-os = 11.0.3pan-os = 11.0.4pan-os = 11.0.5pan-os = 11.0.6pan-os = 11.1.0pan-os = 11.1.1pan-os = 11.1.2pan-os = 11.1.3pan-os = 11.1.4pan-os = 11.1.5pan-os = 11.2.0pan-os = 11.2.1pan-os = 11.2.2pan-os = 11.2.3pan-os = 11.2.4Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
Field changes observed since this record was first indexed.
Connected by shared product, vendor, weakness, or advisory.
CVE-2024-9474High· 7.2A privilege escalation vulnerability in Palo Alto Networks PAN-OS software allows a PAN-OS administrator with access to the management web interface to perform actions on the firewall with root privileges. Cloud NGFW and Prisma Access a…
CVE-2019-1579High· 8.1Remote Code Execution in PAN-OS 7.1.18 and earlier, PAN-OS 8.0.11-h1 and earlier, and PAN-OS 8.1.2 and earlier with GlobalProtect Portal or GlobalProtect Gateway Interface enabled may allow an unauthenticated remote attacker to execute a…
CVE-2019-5591Medium· 6.5A Default Configuration vulnerability in FortiOS may allow an unauthenticated attacker on the same subnet to intercept sensitive information by impersonating the LDAP server.
CVE-2024-51567Critical· 10.0upgrademysqlstatus in databases/views.py in CyberPanel (aka Cyber Panel) before 5b08cd6 allows remote attackers to bypass authentication and execute arbitrary commands via /dataBases/upgrademysqlstatus by bypassing secMiddleware (which i…
CVE-2025-3248Critical· 9.8Langflow versions prior to 1.3.0 are susceptible to code injection in the /api/v1/validate/code endpoint
CVE-2024-11680Critical· 9.8ProjectSend versions prior to r1720 are affected by an improper authentication vulnerability