FortiGuard Outbreak Alert: Palo Alto Networks Management Interface Attack
| Description | Palo Alto Networks PAN-OS software is an OS that runs on Palo Alto Networks firewalls. The management interface for PAN-OS is vulnerable to the following CVEs: CVE-2024-0012 is an authentication bypass vulnerability in PAN-OS that allows unauthenticated attackers to gain administrator privileges. CVE-2024-9474 is a privilege escalation vulnerability in PAN-OS that allows PAN-OS administrator to perform actions with root privileges. The following versions of PAN-OS is vulnerable to CVE-2024-0012 and CVE-2024-9474: PAN-OS 11.2: < 11.2.4-h1 | |||||||||
| CVE ID | CVE-2024-0012 (https://nvd.nist.gov/vuln/detail/CVE-2024-0012) | |||||||||
| NDR Cloud Detection Rule | FortiNDR Cloud v2024.10+
| |||||||||
| Playbook | N/A | |||||||||
| Threat Hunting | FortiNDR Cloud users can use the following IOCs from Fortinet to hunt for “Palo Alto Networks Management Interface Attack” related activities | |||||||||
| Suricata Coverage | Customers can create custom investigation/detections using the Suricata signatures below: | |||||||||
| Other Fortinet Products | For more details regarding mitigating the vulnerability by utilizing Fortinet products, please refer to |
