PAN-OS Flaws Chained for Admin Takeover
Palo Alto Networks PAN-OS web management interface flaws CVE-2024-0012 and CVE-2024-9474 are being actively exploited to gain admin access and escalate privileges.
The Japan IPA has issued an alert regarding two vulnerabilities affecting Palo Alto Networks PAN-OS web management interfaces: an authentication bypass (CVE-2024-0012) and a privilege escalation flaw (CVE-2024-9474). When chained together, these vulnerabilities allow an unauthenticated remote attacker to gain administrator-level access, modify configurations, and escalate privileges on affected devices.
Palo Alto Networks has confirmed that exploitation of these vulnerabilities is already occurring in the wild, prompting IPA to warn that damage may expand if organizations do not act quickly. Cloud NGFW and Prisma Access products are reportedly not affected by this issue. IPA recommends that organizations using vulnerable PAN-OS versions apply the vendor-released patched versions as soon as possible and consult Palo Alto Networks' advisory for detailed remediation guidance.
Mentioned in this report
Source reporting: https://www.ipa.go.jp/security/security-alert/2024/alert20241119.html
This is the public brief
Subscribers see the full picture: extracted IOCs, ready-to-deploy detections (Sigma, Splunk, KQL, Elastic, YARA, Suricata), the entity graph, TAXII 2.1 feed and real-time alerts matched to your sectors.
Start free