Skip to content
COOEY

EXPOSURES › CVE-2024-0012

CVE-2024-0012

CRITICAL ⌖ ON CISA KEV · EXPLOITED
DETAIL
SourceCISA-KEV · kev Published2024-11-18 Referencehttps://nvd.nist.gov/vuln/detail/CVE-2024-0012 ↗
⚡ RCE ⌖ EXPLOITED IN THE WILD SHAME 85/100 ransomwareexploited-in-wildunpatchedrceauth-bypassnegligence

Palo Alto Networks PAN-OS firewalls and VPN concentrators suffered an authentication bypass vulnerability in their web management interface that was actively exploited in the wild and linked to ransomware attacks.

The authentication bypass flaw allowed attackers to access the management interface without valid credentials, enabling remote code execution and full device compromise. This is a critical failure for DIB organizations relying on Palo Alto firewalls for network security, as it directly undermines their perimeter defenses and violates CMMC/NIST 800-171 requirements for protecting unclassified information. Organizations must immediately patch PAN-OS and review their network segmentation and access control policies.

Shame score — A critical authentication bypass in a leading firewall vendor's management interface was actively exploited in the wild and linked to ransomware, demonstrating severe negligence in patching and security design.

▸ RECOMMENDED ACTION  Actively exploited (CISA KEV) — remediate now, ahead of your normal patch cycle.

DESCRIPTION

Palo Alto Networks PAN-OS contains an authentication bypass vulnerability in the web-based management interface for several PAN-OS products, including firewalls and VPN concentrators.

AFFECTED FEDRAMP PRODUCTS · 2
PRODUCTSTATUS
GCS-HIGH
Palo Alto Networks, Inc.
Ready
Palo Alto Networks Government Cloud Services
Palo Alto Networks, Inc.
Authorized