# Palo Alto PAN-OS flaws exploited in wild

Published: 2024-11-18 · Severity: critical
Canonical: https://vorant.io/reports/77b0d5e9-8384-5354-8b2d-1d70c2765a8e/palo-alto-pan-os-flaws-exploited-in-wild

> Authentication bypass (CVE-2024-0012) and privilege escalation (CVE-2024-9474) flaws in PAN-OS web management interface are under active exploitation, allowing unauthenticated remote attackers to gain admin access.

Japan's IPA has issued an alert regarding two vulnerabilities in Palo Alto Networks' PAN-OS affecting the web management interface. CVE-2024-0012 is an authentication bypass flaw, while CVE-2024-9474 is a privilege escalation vulnerability. When chained together, these flaws allow unauthenticated remote attackers to obtain administrator privileges, modify configurations, and escalate privileges on affected systems.

Palo Alto Networks has confirmed active exploitation of these vulnerabilities in the wild. The vendor has released patched versions to address both flaws. Cloud NGFW and Prisma Access products are not affected by these vulnerabilities.

IPA warns that attacks may expand and urges organizations to immediately apply the vendor-provided updates. Affected versions span PAN-OS 11.2, 11.1, 11.0, and 10.2 releases, with specific fixed versions available for each branch.

## Mentioned in this report

- Vulnerabilities: CVE-2024-0012 (KEV), CVE-2024-9474 (KEV)

Source reporting: https://www.ipa.go.jp/security/security-alert/2024/alert20241119.html

---

This is the free public brief from Vorant Threat Intelligence. When citing, attribute "Vorant" and link https://vorant.io/reports/77b0d5e9-8384-5354-8b2d-1d70c2765a8e/palo-alto-pan-os-flaws-exploited-in-wild.
Full IOC sets, deployable detections, the entity graph, TAXII 2.1 feed and real-time alerts: https://vorant.io/signup
