EXPOSURES › CVE-2024-0012
CVE-2024-0012
CRITICAL ⌖ ON CISA KEV · EXPLOITEDPalo Alto Networks PAN-OS firewalls and VPN concentrators suffered an authentication bypass vulnerability in their web management interface that was actively exploited in the wild and linked to ransomware attacks.
The authentication bypass flaw allowed attackers to access the management interface without valid credentials, enabling remote code execution and full device compromise. This is a critical failure for DIB organizations relying on Palo Alto firewalls for network security, as it directly undermines their perimeter defenses and violates CMMC/NIST 800-171 requirements for protecting unclassified information. Organizations must immediately patch PAN-OS and review their network segmentation and access control policies.
Shame score — A critical authentication bypass in a leading firewall vendor's management interface was actively exploited in the wild and linked to ransomware, demonstrating severe negligence in patching and security design.
▸ RECOMMENDED ACTION Actively exploited (CISA KEV) — remediate now, ahead of your normal patch cycle.
Palo Alto Networks PAN-OS contains an authentication bypass vulnerability in the web-based management interface for several PAN-OS products, including firewalls and VPN concentrators.
| PRODUCT | STATUS |
|---|---|
| GCS-HIGH Palo Alto Networks, Inc. |
Ready |
| Palo Alto Networks Government Cloud Services Palo Alto Networks, Inc. |
Authorized |