CVE-2024-0012: PAN-OS: Authentication Bypass in the Management Web Interface (PAN-SA-2024-0015) (Severity: CRITICAL)
An authentication bypass in Palo Alto Networks PAN-OS software enables an unauthenticated attacker with network access to the management web interface to gain PAN-OS administrator privileges to perform administrative actions, tamper with the configuration, or exploit other authenticated privilege escalation vulnerabilities like CVE-2024-9474 https://security.paloaltonetworks.com/CVE-2024-9474 .
The risk of this issue is greatly reduced if you secure access to the management web interface by restricting access to only trusted internal IP addresses according to our recommended best practice deployment guidelines https://live.paloaltonetworks.com/t5/community-blogs/tips-amp-tricks-how-to-secure-the-management-access-of-your-palo/ba-p/464431 .
This issue is applicable only to PAN-OS 10.2, PAN-OS 11.0, PAN-OS 11.1, and PAN-OS 11.2 software.
Cloud NGFW and Prisma Access are not impacted by this vulnerability.
Other sources
An authentication bypass in Palo Alto Networks PAN-OS software enables an unauthenticated attacker with network access to the management web interface to gain PAN-OS administrator privileges to perform administrative actions, tamper with the configuration, or exploit other authenticated privilege escalation vulnerabilities like CVE-2024-9474 (https://security.paloaltonetworks.com/CVE-2024-9474).
The risk of this issue is greatly reduced if you secure access to the management web interface by restricting access to only trusted internal IP addresses according to our recommended best practice deployment guidelines (https://live.paloaltonetworks.com/t5/community-blogs/tips-amp-tricks-how-to-secure-the-management-access-of-your-palo/ba-p/464431).
This issue is applicable only to PAN-OS 10.2, PAN-OS 11.0, PAN-OS 11.1, and PAN-OS 11.2 software on PA-Series, VM-Series, and CN-Series firewalls and on Panorama (virtual and M-Series).
Cloud NGFW and Prisma Access are not impacted by this vulnerability.
— Palo Alto Networks
Palo Alto Networks PAN-OS contains an authentication bypass vulnerability in the web-based management interface for several PAN-OS products, including firewalls and VPN concentrators.
— CISA
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
Palo Alto PAN-OSto a version that resolves this vulnerability.Fixed in 11.2.4-h1Fixed in 11.2.1-h1Fixed in 11.2.2-h2Fixed in 11.2.3-h3Fixed in 11.2.0-h1Fixed in 11.1.5-h1Fixed in 11.1.0-h4Fixed in 11.1.1-h2Fixed in 11.1.2-h15Fixed in 11.1.3-h11Fixed in 11.1.4-h7Fixed in 11.0.6-h1Fixed in 11.0.0-h4Fixed in 11.0.1-h5Fixed in 11.0.2-h5Fixed in 11.0.3-h13Fixed in 11.0.4-h6Fixed in 11.0.5-h2Fixed in 10.2.0-h4Fixed in 10.2.1-h3Fixed in 10.2.2-h6Fixed in 10.2.3-h14Fixed in 10.2.4-h32Fixed in 10.2.5-h9Fixed in 10.2.6-h6Fixed in 10.2.7-h18Fixed in 10.2.8-h15Fixed in 10.2.9-h16Fixed in 10.2.10-h9Fixed in 10.2.11-h6 - Upgrade
Upgrade
Palo Alto Networks PAN-OSto a version that resolves this vulnerability.Fixed in 10.2.12-h2Patch PAN-SA-2024-0015 - Upgrade
Upgrade
Palo Alto Networks PAN-OSto a version that resolves this vulnerability.Fixed in 11.0.6-h1Patch PAN-SA-2024-0015 - Upgrade
Upgrade
Palo Alto Networks PAN-OSto a version that resolves this vulnerability.Fixed in 11.1.5-h1Patch PAN-SA-2024-0015 - Upgrade
Upgrade
Palo Alto Networks PAN-OSto a version that resolves this vulnerability.Fixed in 11.2.4-h1Patch PAN-SA-2024-0015 - Configuration
Enable threat prevention on the inbound traffic to management services so threat signatures can block the authentication bypass attempts.
PAN-OS management interface (inbound traffic to management services) Enable threat prevention = enabled - Configuration
Ensure the Threat IDs 95746, 95747, 95752, 95753, 95759, and 95763 are set to block mode (requires Threat Prevention subscription; listed as available in Applications and Threats content version 8915-9075 and later).
PAN-OS threat prevention Threat ID block mode = block - Configuration
Decrypt inbound traffic to the management interface so the firewall can inspect it.
PAN-OS management interface inbound traffic inspection Decrypt inbound traffic = enabled - Configuration
Replace the Certificate for Inbound Traffic Management.
PAN-OS inbound traffic management (certificate used for management traffic) Replace certificate = replaced - Configuration
Route incoming traffic for the MGT port through a DP (data plane) port, e.g., by enabling management profile on a DP interface for management access.
PAN-OS management (routing for MGT port) Route incoming MGT traffic through DP = enabled - Compensating control
Restrict access to the PAN-OS management interface so it is not exposed to untrusted networks, including the internet (allow only trusted internal IP addresses).
Event History
Frequently Asked Questions
What is the severity of CVE-2024-0012?
CVE-2024-0012 is classified as a high severity vulnerability due to its potential to allow unauthenticated attackers to gain administrator privileges.
How do I fix CVE-2024-0012?
To remediate CVE-2024-0012, upgrade to PAN-OS version 10.2.12, 11.0.6, 11.1.5, or 11.2.4 or later, as applicable.
What systems are affected by CVE-2024-0012?
CVE-2024-0012 affects Palo Alto Networks PAN-OS versions 10.2.0 through 10.2.12, 11.0.0 through 11.0.6, 11.1.0 through 11.1.5, and 11.2.0 through 11.2.4.
What actions can an attacker take exploiting CVE-2024-0012?
An attacker exploiting CVE-2024-0012 can perform administrative actions, tamper with configuration settings, and potentially exploit other vulnerabilities.
Is there a workaround for CVE-2024-0012?
There are no documented workarounds for CVE-2024-0012, so it is recommended to apply the necessary updates to affected systems.