Description |
Palo Alto Networks PAN-OS software is an OS that runs on Palo Alto Networks firewalls. The management interface for PAN-OS is vulnerable to the following CVEs: CVE-2024-0012 is an authentication bypass vulnerability in PAN-OS that allows unauthenticated attackers to gain administrator privileges. CVE-2024-9474 is a privilege escalation vulnerability in PAN-OS that allows PAN-OS administrator to perform actions with root privileges. The following versions of PAN-OS is vulnerable to CVE-2024-0012 and CVE-2024-9474: PAN-OS 11.2: < 11.2.4-h1 |
|||||||||
CVE ID |
CVE-2024-0012 (https://nvd.nist.gov/vuln/detail/CVE-2024-0012) |
|||||||||
NDR Cloud Detection Rule |
FortiNDR Cloud v2024.10+
|
|||||||||
Playbook |
N/A |
|||||||||
Threat Hunting |
FortiNDR Cloud users can use the following IOCs from Fortinet to hunt for “Palo Alto Networks Management Interface Attack” related activities |
|||||||||
Suricata Coverage |
Customers can create custom investigation/detections using the Suricata signatures below: |
|||||||||
Other Fortinet Products |
For more details regarding mitigating the vulnerability by utilizing Fortinet products, please refer to |
The Fortinet Security Fabric brings together the concepts of convergence and consolidation to provide comprehensive cybersecurity protection for all users, devices, and applications and across all network edges.
Copyright 2024 Fortinet, Inc. All Rights Reserved.