VORANT. Threat Intelligence Sign in Get the full feed

Palo Alto PAN-OS flaws exploited in wild

critical vulnerability

Authentication bypass (CVE-2024-0012) and privilege escalation (CVE-2024-9474) flaws in PAN-OS web management interface are under active exploitation, allowing unauthenticated remote attackers to gain admin access.

Japan's IPA has issued an alert regarding two vulnerabilities in Palo Alto Networks' PAN-OS affecting the web management interface. CVE-2024-0012 is an authentication bypass flaw, while CVE-2024-9474 is a privilege escalation vulnerability. When chained together, these flaws allow unauthenticated remote attackers to obtain administrator privileges, modify configurations, and escalate privileges on affected systems.

Palo Alto Networks has confirmed active exploitation of these vulnerabilities in the wild. The vendor has released patched versions to address both flaws. Cloud NGFW and Prisma Access products are not affected by these vulnerabilities.

IPA warns that attacks may expand and urges organizations to immediately apply the vendor-provided updates. Affected versions span PAN-OS 11.2, 11.1, 11.0, and 10.2 releases, with specific fixed versions available for each branch.

Mentioned in this report

Vulnerabilities CVE-2024-0012KEVCVE-2024-9474KEV

Source reporting: https://www.ipa.go.jp/security/security-alert/2024/alert20241119.html

This is the public brief

Subscribers see the full picture: extracted IOCs, ready-to-deploy detections (Sigma, Splunk, KQL, Elastic, YARA, Suricata), the entity graph, TAXII 2.1 feed and real-time alerts matched to your sectors.

Start free