Description
An authentication bypass in Palo Alto Networks PAN-OS software enables an unauthenticated attacker with network access to the management web interface to gain PAN-OS administrator privileges to perform administrative actions, tamper with the configuration, or exploit other authenticated privilege escalation vulnerabilities like CVE-2024-9474 https://security.paloaltonetworks.com/CVE-2024-9474 . The risk of this issue is greatly reduced if you secure access to the management web interface by restricting access to only trusted internal IP addresses according to our recommendedΒ best practice deployment guidelines https://live.paloaltonetworks.com/t5/community-blogs/tips-amp-tricks-how-to-secure-the-management-access-of-your-palo/ba-p/464431 . This issue is applicable only to PAN-OS 10.2, PAN-OS 11.0, PAN-OS 11.1, and PAN-OS 11.2 software. Cloud NGFW and Prisma Access are not impacted by this vulnerability.
CVSS breakdown
Affected products
- Palo Alto Networks / Cloud NGFWAll β All
- Palo Alto Networks / Prisma AccessAll β All
- paloaltonetworks / pan-os11.2.3 β 11.2.3
- paloaltonetworks / pan-os11.2.2 β 11.2.2
- paloaltonetworks / pan-os11.2.1 β 11.2.1
- paloaltonetworks / pan-os11.2.0 β 11.2.0
- paloaltonetworks / pan-os11.2 β 11.2
- paloaltonetworks / pan-os11.1.5 β 11.1.5
- paloaltonetworks / pan-os11.1.4 β 11.1.4
- paloaltonetworks / pan-os11.1.4 β 11.1.4
- paloaltonetworks / pan-os11.1.4 β 11.1.4
- paloaltonetworks / pan-os11.1.4 β 11.1.4
- paloaltonetworks / pan-os11.1.4 β 11.1.4
- paloaltonetworks / pan-os11.1.3 β 11.1.3
- paloaltonetworks / pan-os11.1.3 β 11.1.3
- paloaltonetworks / pan-os11.1.3 β 11.1.3
- paloaltonetworks / pan-os11.1.3 β 11.1.3
- paloaltonetworks / pan-os11.1.3 β 11.1.3
- paloaltonetworks / pan-os11.1.3 β 11.1.3
- paloaltonetworks / pan-os11.1.3 β 11.1.3
- paloaltonetworks / pan-os11.1.3 β 11.1.3
- paloaltonetworks / pan-os11.1.3 β 11.1.3
- paloaltonetworks / pan-os11.1.3 β 11.1.3
- paloaltonetworks / pan-os11.1.2 β 11.1.2
- paloaltonetworks / pan-os11.1.2 β 11.1.2
- paloaltonetworks / pan-os11.1.2 β 11.1.2
- paloaltonetworks / pan-os11.1.2 β 11.1.2
- paloaltonetworks / pan-os11.1.2 β 11.1.2
- paloaltonetworks / pan-os11.1.2 β 11.1.2
- paloaltonetworks / pan-os11.1.2 β 11.1.2
- paloaltonetworks / pan-os11.1.2 β 11.1.2
- paloaltonetworks / pan-os11.1.2 β 11.1.2
- paloaltonetworks / pan-os11.1.2 β 11.1.2
- paloaltonetworks / pan-os11.1.2 β 11.1.2
- paloaltonetworks / pan-os11.1.2 β 11.1.2
- paloaltonetworks / pan-os11.1.2 β 11.1.2
- paloaltonetworks / pan-os11.1.2 β 11.1.2
- paloaltonetworks / pan-os11.1.2 β 11.1.2
- paloaltonetworks / pan-os11.1.1 β 11.1.1
- paloaltonetworks / pan-os11.1.1 β 11.1.1
- paloaltonetworks / pan-os11.1.0 β 11.1.0
- paloaltonetworks / pan-os11.1.0 β 11.1.0
- paloaltonetworks / pan-os11.1.0 β 11.1.0
- paloaltonetworks / pan-os11.1.0 β 11.1.0
- paloaltonetworks / pan-os11.1 β 11.1
- paloaltonetworks / pan-os11.0.6 β 11.0.6
- paloaltonetworks / pan-os11.0.5 β 11.0.5
- paloaltonetworks / pan-os11.0.5 β 11.0.5
- paloaltonetworks / pan-os11.0.4 β 11.0.4
- paloaltonetworks / pan-os11.0.4 β 11.0.4
- paloaltonetworks / pan-os11.0.4 β 11.0.4
- paloaltonetworks / pan-os11.0.4 β 11.0.4
- paloaltonetworks / pan-os11.0.4 β 11.0.4
- paloaltonetworks / pan-os11.0.4 β 11.0.4
- paloaltonetworks / pan-os11.0.3 β 11.0.3
- paloaltonetworks / pan-os11.0.3 β 11.0.3
- paloaltonetworks / pan-os11.0.3 β 11.0.3
- paloaltonetworks / pan-os11.0.3 β 11.0.3
- paloaltonetworks / pan-os11.0.3 β 11.0.3
- paloaltonetworks / pan-os11.0.3 β 11.0.3
- paloaltonetworks / pan-os11.0.3 β 11.0.3
- paloaltonetworks / pan-os11.0.3 β 11.0.3
- paloaltonetworks / pan-os11.0.3 β 11.0.3
- paloaltonetworks / pan-os11.0.3 β 11.0.3
- paloaltonetworks / pan-os11.0.3 β 11.0.3
- paloaltonetworks / pan-os11.0.3 β 11.0.3
- paloaltonetworks / pan-os11.0.3 β 11.0.3
- paloaltonetworks / pan-os11.0.2 β 11.0.2
- paloaltonetworks / pan-os11.0.2 β 11.0.2
- paloaltonetworks / pan-os11.0.2 β 11.0.2
- paloaltonetworks / pan-os11.0.2 β 11.0.2
- paloaltonetworks / pan-os11.0.2 β 11.0.2
- paloaltonetworks / pan-os11.0.1 β 11.0.1
- paloaltonetworks / pan-os11.0.1 β 11.0.1
- paloaltonetworks / pan-os11.0.1 β 11.0.1
- paloaltonetworks / pan-os11.0.1 β 11.0.1
- paloaltonetworks / pan-os11.0.1 β 11.0.1
- paloaltonetworks / pan-os11.0.0 β 11.0.0
- paloaltonetworks / pan-os11.0.0 β 11.0.0
- paloaltonetworks / pan-os11.0.0 β 11.0.0
- paloaltonetworks / pan-os11.0.0 β 11.0.0
- paloaltonetworks / pan-os11.0 β 11.0
- paloaltonetworks / pan-os10.2.12 β 10.2.12
- paloaltonetworks / pan-os10.2.12 β 10.2.12
- paloaltonetworks / pan-os10.2.11 β 10.2.11
- paloaltonetworks / pan-os10.2.11 β 10.2.11
- paloaltonetworks / pan-os10.2.11 β 10.2.11
- paloaltonetworks / pan-os10.2.11 β 10.2.11
- paloaltonetworks / pan-os10.2.11 β 10.2.11
- paloaltonetworks / pan-os10.2.10 β 10.2.10
- paloaltonetworks / pan-os10.2.10 β 10.2.10
- paloaltonetworks / pan-os10.2.10 β 10.2.10
- paloaltonetworks / pan-os10.2.10 β 10.2.10
- paloaltonetworks / pan-os10.2.10 β 10.2.10
- paloaltonetworks / pan-os10.2.10 β 10.2.10
- paloaltonetworks / pan-os10.2.10 β 10.2.10
- paloaltonetworks / pan-os10.2.10 β 10.2.10
- paloaltonetworks / pan-os10.2.9 β 10.2.9
- paloaltonetworks / pan-os10.2.9 β 10.2.9
- paloaltonetworks / pan-os10.2.9 β 10.2.9
- paloaltonetworks / pan-os10.2.9 β 10.2.9
- paloaltonetworks / pan-os10.2.9 β 10.2.9
- paloaltonetworks / pan-os10.2.9 β 10.2.9
- paloaltonetworks / pan-os10.2.9 β 10.2.9
- paloaltonetworks / pan-os10.2.9 β 10.2.9
- paloaltonetworks / pan-os10.2.9 β 10.2.9
- paloaltonetworks / pan-os10.2.9 β 10.2.9
- paloaltonetworks / pan-os10.2.9 β 10.2.9
- paloaltonetworks / pan-os10.2.9 β 10.2.9
- paloaltonetworks / pan-os10.2.9 β 10.2.9
- paloaltonetworks / pan-os10.2.9 β 10.2.9
- paloaltonetworks / pan-os10.2.9 β 10.2.9
- paloaltonetworks / pan-os10.2.8 β 10.2.8
- paloaltonetworks / pan-os10.2.8 β 10.2.8
- paloaltonetworks / pan-os10.2.8 β 10.2.8
- paloaltonetworks / pan-os10.2.8 β 10.2.8
- paloaltonetworks / pan-os10.2.8 β 10.2.8
- paloaltonetworks / pan-os10.2.8 β 10.2.8
- paloaltonetworks / pan-os10.2.8 β 10.2.8
- paloaltonetworks / pan-os10.2.8 β 10.2.8
- paloaltonetworks / pan-os10.2.8 β 10.2.8
- paloaltonetworks / pan-os10.2.8 β 10.2.8
- paloaltonetworks / pan-os10.2.8 β 10.2.8
- paloaltonetworks / pan-os10.2.8 β 10.2.8
- paloaltonetworks / pan-os10.2.8 β 10.2.8
- paloaltonetworks / pan-os10.2.8 β 10.2.8
- paloaltonetworks / pan-os10.2.7 β 10.2.7
- paloaltonetworks / pan-os10.2.7 β 10.2.7
- paloaltonetworks / pan-os10.2.7 β 10.2.7
- paloaltonetworks / pan-os10.2.7 β 10.2.7
- paloaltonetworks / pan-os10.2.7 β 10.2.7
- paloaltonetworks / pan-os10.2.7 β 10.2.7
- paloaltonetworks / pan-os10.2.7 β 10.2.7
- paloaltonetworks / pan-os10.2.7 β 10.2.7
- paloaltonetworks / pan-os10.2.7 β 10.2.7
- paloaltonetworks / pan-os10.2.7 β 10.2.7
- paloaltonetworks / pan-os10.2.7 β 10.2.7
- paloaltonetworks / pan-os10.2.7 β 10.2.7
- paloaltonetworks / pan-os10.2.7 β 10.2.7
- paloaltonetworks / pan-os10.2.7 β 10.2.7
- paloaltonetworks / pan-os10.2.7 β 10.2.7
- paloaltonetworks / pan-os10.2.7 β 10.2.7
- paloaltonetworks / pan-os10.2.7 β 10.2.7
- paloaltonetworks / pan-os10.2.6 β 10.2.6
- paloaltonetworks / pan-os10.2.6 β 10.2.6
- paloaltonetworks / pan-os10.2.6 β 10.2.6
- paloaltonetworks / pan-os10.2.6 β 10.2.6
- paloaltonetworks / pan-os10.2.5 β 10.2.5
- paloaltonetworks / pan-os10.2.5 β 10.2.5
- paloaltonetworks / pan-os10.2.5 β 10.2.5
- paloaltonetworks / pan-os10.2.5 β 10.2.5
- paloaltonetworks / pan-os10.2.5 β 10.2.5
- paloaltonetworks / pan-os10.2.5 β 10.2.5
- paloaltonetworks / pan-os10.2.5 β 10.2.5
- paloaltonetworks / pan-os10.2.4 β 10.2.4
- paloaltonetworks / pan-os10.2.4 β 10.2.4
- paloaltonetworks / pan-os10.2.4 β 10.2.4
- paloaltonetworks / pan-os10.2.4 β 10.2.4
- paloaltonetworks / pan-os10.2.4 β 10.2.4
- paloaltonetworks / pan-os10.2.4 β 10.2.4
- paloaltonetworks / pan-os10.2.4 β 10.2.4
- paloaltonetworks / pan-os10.2.4 β 10.2.4
- paloaltonetworks / pan-os10.2.4 β 10.2.4
- paloaltonetworks / pan-os10.2.4 β 10.2.4
- paloaltonetworks / pan-os10.2.4 β 10.2.4
- paloaltonetworks / pan-os10.2.4 β 10.2.4
- paloaltonetworks / pan-os10.2.4 β 10.2.4
- paloaltonetworks / pan-os10.2.4 β 10.2.4
- paloaltonetworks / pan-os10.2.4 β 10.2.4
- paloaltonetworks / pan-os10.2.4 β 10.2.4
- paloaltonetworks / pan-os10.2.4 β 10.2.4
- paloaltonetworks / pan-os10.2.3 β 10.2.3
- paloaltonetworks / pan-os10.2.3 β 10.2.3
- paloaltonetworks / pan-os10.2.3 β 10.2.3
- paloaltonetworks / pan-os11.1.3 β 11.1.3
- paloaltonetworks / pan-os10.2.3 β 10.2.3
- paloaltonetworks / pan-os10.2.3 β 10.2.3
- paloaltonetworks / pan-os10.2.3 β 10.2.3
- paloaltonetworks / pan-os10.2.3 β 10.2.3
- paloaltonetworks / pan-os10.2.3 β 10.2.3
- paloaltonetworks / pan-os10.2.3 β 10.2.3
- paloaltonetworks / pan-os10.2.3 β 10.2.3
- paloaltonetworks / pan-os10.2.3 β 10.2.3
- paloaltonetworks / pan-os10.2.3 β 10.2.3
- paloaltonetworks / pan-os10.2.3 β 10.2.3
- paloaltonetworks / pan-os10.2.2 β 10.2.2
- paloaltonetworks / pan-os10.2.2 β 10.2.2
- paloaltonetworks / pan-os10.2.2 β 10.2.2
- paloaltonetworks / pan-os10.2.2 β 10.2.2
- paloaltonetworks / pan-os10.2.2 β 10.2.2
- paloaltonetworks / pan-os10.2.2 β 10.2.2
- paloaltonetworks / pan-os10.2.1 β 10.2.1
- paloaltonetworks / pan-os10.2.1 β 10.2.1
- paloaltonetworks / pan-os10.2.1 β 10.2.1
- paloaltonetworks / pan-os10.2.0 β 10.2.0
- paloaltonetworks / pan-os10.2.0 β 10.2.0
- paloaltonetworks / pan-os10.2.0 β 10.2.0
- paloaltonetworks / pan-os10.2.0 β 10.2.0
- paloaltonetworks / pan-os10.2 β 10.2
- paloaltonetworks / pan-os10.2.3 β 10.2.3
- paloaltonetworks / pan-os11.2.4 β 11.2.4
Exploits & PoCs
- nucleiPAN-OS Management Web Interface - Authentication Bypassby johnk3r,watchtowr