# PAN-OS Flaws Chained for Admin Takeover

Published: 2024-11-18 · Severity: high
Canonical: https://vorant.io/reports/77b0d5e9-8384-5354-8b2d-1d70c2765a8e/pan-os-flaws-chained-for-admin-takeover

> Palo Alto Networks PAN-OS web management interface flaws CVE-2024-0012 and CVE-2024-9474 are being actively exploited to gain admin access and escalate privileges.

The Japan IPA has issued an alert regarding two vulnerabilities affecting Palo Alto Networks PAN-OS web management interfaces: an authentication bypass (CVE-2024-0012) and a privilege escalation flaw (CVE-2024-9474). When chained together, these vulnerabilities allow an unauthenticated remote attacker to gain administrator-level access, modify configurations, and escalate privileges on affected devices.

Palo Alto Networks has confirmed that exploitation of these vulnerabilities is already occurring in the wild, prompting IPA to warn that damage may expand if organizations do not act quickly. Cloud NGFW and Prisma Access products are reportedly not affected by this issue. IPA recommends that organizations using vulnerable PAN-OS versions apply the vendor-released patched versions as soon as possible and consult Palo Alto Networks' advisory for detailed remediation guidance.

## Mentioned in this report

- Vulnerabilities: CVE-2024-0012 (KEV), CVE-2024-9474 (KEV)

Source reporting: https://www.ipa.go.jp/security/security-alert/2024/alert20241119.html

---

This is the free public brief from Vorant Threat Intelligence. When citing, attribute "Vorant" and link https://vorant.io/reports/77b0d5e9-8384-5354-8b2d-1d70c2765a8e/pan-os-flaws-chained-for-admin-takeover.
Full IOC sets, deployable detections, the entity graph, TAXII 2.1 feed and real-time alerts: https://vorant.io/signup
