Sploitus

CVE-2024-0012

27 known exploits for CVE-2024-0012

An authentication bypass in Palo Alto Networks PAN-OS software enables an unauthenticated attacker with network access to the management web interface to gain PAN-OS administrator privileges to perform administrative actions, tamper with the configuration, or exploit other authenticated privilege escalation vulnerabilities like CVE-2024-9474 https://security.paloaltonetworks.com/CVE-2024-9474 . The risk of this issue is greatly reduced if you secure access to the management web interface by restricting access to only trusted internal IP addresses according to our recommended  best practice deployment guidelines https://live.paloaltonetworks.com/t5/community-blogs/tips-amp-tricks-how-to-secure-the-management-access-of-your-palo/ba-p/464431 . This issue is applicable only to PAN-OS 10.2, PAN-OS 11.0, PAN-OS 11.1, and PAN-OS 11.2 software. Cloud NGFW and Prisma Access are not impacted by this vulnerability.

Affected products
Pan-Os
Paloaltonetworks Pan-os
= 10.2.0, 10.2.1, 10.2.2, 10.2.3, 10.2.4, 10.2.5, 10.2.6, 10.2.7, 10.2.8, 10.2.9, 10.2.10, 10.2.11, 10.2.12, 11.0.0, 11.0.1, 11.0.2, 11.0.3, 11.0.4, 11.0.5, 11.0.6, 11.1.0, 11.1.1, 11.1.2, 11.1.3, 11.1.4, 11.1.5, 11.2.0, 11.2.1, 11.2.2, 11.2.3, 11.2.4
Fix
Available
CVSS 3.1
9.8 CRITICAL
EPSS
99.7% (100th percentile)
Weakness
CWE-306
NVD status
Analyzed
Published
2024-11-18
Attack patterns
CAPEC-115
Entry point
user request body
Path
php/utils/createRemoteAppwebSession.php

Workaround

Recommended mitigation—The vast majority of firewalls already follow Palo Alto Networks and industry best practices. However, if you haven’t already, we strongly recommend that you secure access to your management interface according to our best practice deployment guidelines. Specifically, you should restrict access to the management interface to only trusted internal IP addresses to prevent external access from the internet. Additionally, if you have a Threat Prevention subscription, you can block these attacks using Threat IDs 95746, 95747, 95752, 95753, 95759, and 95763 (available in Applications and Threats content version 8915-9075 and later). For these Threat IDs to protect against attacks for this vulnerability, * Ensure that all the listed Threat IDs are set to block mode, * Route incoming traffic for the MGT port through a DP port https://docs.paloaltonetworks.com/best-practices/10-1/administrative-access-best-practices/administrative-access-best-practices/deploy-administrative-access-best-practices#id59206398-3dab-4b2f-9b4b-7ea500d036ba , e.g., enabling management profile on a DP interface for management access, * Replace the Certificate for Inbound Traffic Management h…

CVE-2024-0012 at NVD
Authoritative description, scoring and affected products

27 known exploits for CVE-2024-0012

Proof-of-concept code and exploit modules indexed by Sploitus

CVE-2024-0012-poc
2026-09-01 KitPloitKITPLOIT
CVE-2024-0012_CVE-2024-9474_PoC
2026-09-01 KitPloitKITPLOIT
CVE-2024-9474
2026-09-01 KitPloitKITPLOIT
CVE-2024-0012-POC
2026-09-01 KitPloitKITPLOIT
PanOsExploitMultitool
2026-09-01 KitPloitKITPLOIT
cve-2024-0012_9474-panos_authbypass_reproduction
2026-09-01 KitPloitKITPLOIT
CVE-2024-0012
2026-09-01 KitPloitKITPLOIT
CVE-2024-9474
2026-08-31 KitPloitKITPLOIT
cve-2024-0012-gui-poc
2026-08-31 KitPloitKITPLOIT
CVE-2024-0012
2026-08-31 KitPloitKITPLOIT
palo-alto-panos-cve-2024-0012
2026-08-29 KitPloitKITPLOIT
cve-2024-0012-poc
2026-08-28 KitPloitKITPLOIT
Paloalto-CVE-2024-0012
2026-08-28 KitPloitKITPLOIT
Exploit for Missing Authentication for Critical Function in Paloaltonetworks Pan-Os
2026-02-15 sh00bxGITHUB
đź“„ Palo Alto Networks PAN-OS 11.2 PHP Code Injection
2026-02-10 indoushkaPACKETSTORMPHP
Exploit for Missing Authentication for Critical Function in Paloaltonetworks Pan-Os
2025-05-21 Regent8SHGITHUB
Exploit for Missing Authentication for Critical Function in Paloaltonetworks Pan-Os
2025-02-06 dcollaoaGITHUB
Exploit for OS Command Injection in Paloaltonetworks Pan-Os
2025-01-16 arataneGITHUB
Exploit for Missing Authentication for Critical Function in Paloaltonetworks Pan-Os
2024-12-11 TalatumLabsGITHUB
Exploit for Missing Authentication for Critical Function in Paloaltonetworks Pan-Os
2024-11-30 0xjessie21GITHUB
Exploit for Missing Authentication for Critical Function in Paloaltonetworks Pan-Os
2024-11-22 iSee857GITHUB
Exploit for Missing Authentication for Critical Function in Paloaltonetworks Pan-Os
2024-11-22 XiaomingXGITHUB
PAN-OS management interface authentication bypass
2024-11-20 SAINT CorporationSAINT
PAN-OS management interface authentication bypass
2024-11-20 SAINT CorporationSAINT
Exploit for Missing Authentication for Critical Function in Paloaltonetworks Pan-Os
2024-11-19 watchtowrlabsGITHUB
Exploit for Missing Authentication for Critical Function in Paloaltonetworks Pan-Os
2024-11-19 SachinartGITHUB
Palo Alto Networks PAN-OS Management Interface Unauthenticated Remote Code Execution
2024-11-18 watchTowr, sfewer-r7METASPLOITRuby