Description
Management Interface of PAN-OS contains an authentication vulnerability that could allow an unauthenticated attacker to access restricted functionality and exploit the RCE vulnerability, CVE-2024-9474, to compromise the system.
Remediation
Upgrade to the latest version of Palo Alto PAN-OS.
References
CVE-2024-0012 PAN-OS: Authentication Bypass in the Management Web Interface (PAN-SA-2024-0015)
CVE-2024-9474 PAN-OS: Privilege Escalation (PE) Vulnerability in the Web Management Interface
Pots and Pans, AKA an SSLVPN - Palo Alto PAN-OS CVE-2024-0012 and CVE-2024-9474
Related Vulnerabilities
MySQL CVE-2015-0500 Vulnerability (CVE-2015-0500)
Sqlite Other Vulnerability (CVE-2022-46908)
Phusion Passenger Permissions, Privileges, and Access Controls Vulnerability (CVE-2013-2119)
phpMyAdmin CVE-2013-3238 Vulnerability (CVE-2013-3238)
Moodle Exposure of Sensitive Information to an Unauthorized Actor Vulnerability (CVE-2012-1159)