CVE-2024-0012 is a critical authentication bypass vulnerability in Palo Alto Networks PAN-OS software versions 10.2, 11.0, 11.1, and 11.2, allowing unauthenticated attackers with network access to the management web interface to gain full administrator privileges. This vulnerability carries a CVSS score of 9.8 (Critical) due to its network-based attack vector, low attack complexity, and complete compromise of confidentiality, integrity, and availability. It is actively exploited in the wild, including in known ransomware campaigns, with public Metasploit modules and Nuclei templates available, and has garnered significant community discussion and media attention.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
10.2.0CPE matchmatch criteria | cpe:2.3:o:paloaltonetworks:pan-os:10.2.0:-:*:*:*:*:*:* | ||
10.2.0CPE matchmatch criteria | cpe:2.3:o:paloaltonetworks:pan-os:10.2.0:h1:*:*:*:*:*:* | ||
10.2.0CPE matchmatch criteria | cpe:2.3:o:paloaltonetworks:pan-os:10.2.0:h2:*:*:*:*:*:* | ||
10.2.0CPE matchmatch criteria | cpe:2.3:o:paloaltonetworks:pan-os:10.2.0:h3:*:*:*:*:*:* | ||
10.2.1CPE matchmatch criteria | cpe:2.3:o:paloaltonetworks:pan-os:10.2.1:-:*:*:*:*:*:* |
CVSS version used by this source: 4.0
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:L/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:N/R:U/V:C/RE:H/U:Red
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.3 Bluesky, 0.3 Mastodon, and 2.4 GitHub mentions.
The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.