S4E just found a high-severity finding from cve-2025-58360 scanner
PlatformPlansPartners
Resources
ToolsBlogDocs
Sign Up →
critical·Product Based Web Vulnerabilities·Updated Nov 20, 2024

CVE-2024-0012 Scanner

CVE-2024-0012 scanner - Authentication Bypass vulnerability in PAN-OS Management Web Interface

Est. Time~10 seconds
Scan TypeSingle Scan
Targetsdomain, ipv4, subdomain
CostFree
3k
Times Used
continuous scan runs
4.1k
Continuously Checked
assets under CS
0
Vulnerabilities Found
confirmed findings
References
🔴
CISA Known Exploited Vulnerability
This CVE is actively exploited in the wild. CISA mandates federal agencies to patch immediately.
CVECVE-2024-0012
9.3
CVSScritical
Exploitable remotely over the internet · no authentication required.

An authentication bypass in Palo Alto Networks PAN-OS software enables an unauthenticated attacker with network access to the management web interface to gain PAN-OS administrator privileges to perform administrative actions, tamper with the configuration, or exploit other authenticated privilege escalation vulnerabilities like CVE-2024-9474 https://security.paloaltonetworks.com/CVE-2024-9474 . The risk of this issue is greatly reduced if you secure access to the management web interface by restricting access to only trusted internal IP addresses according to our recommended  best practice deployment guidelines https://live.paloaltonetworks.com/t5/community-blogs/tips-amp-tricks-how-to-secure-the-management-access-of-your-palo/ba-p/464431 . This issue is applicable only to PAN-OS 10.2, PAN-OS 11.0, PAN-OS 11.1, and PAN-OS 11.2 software. Cloud NGFW and Prisma Access are not impacted by this vulnerability.

Attack Vector
Network
Privileges Req.
None
User Interaction
None
Affected
Cloud NGFWby Palo Alto Networks
All
PAN-OSby Palo Alto Networks
AFFECTED< 11.2.4-h1SAFE ✓≥ 11.2.4-h1
Prisma Accessby Palo Alto Networks
All
Updated Aug 22, 2026View on NVD →
Detail

The PAN-OS Management Web Interface is an administrative control panel used for configuring Palo Alto Networks firewalls and security appliances. It is widely employed by IT administrators in enterprise networks, government organizations, and managed security service providers. Its primary purpose is to facilitate secure management of firewall rules, user access, and network configurations. The interface is accessible via a web browser and provides granular access controls for different user roles. This interface is critical for maintaining the security posture of the network.

The Authentication Bypass vulnerability in PAN-OS Management Web Interface allows unauthenticated attackers to gain administrator privileges. Exploiting this vulnerability can lead to complete control over the appliance and its configurations. This poses a significant security risk as it could enable attackers to modify settings, disable defenses, and launch further attacks. The issue has been classified as critical due to its severity and potential impact.

The vulnerability exists due to improper handling of authentication requests in the management web interface. Specifically, a crafted request sent to the /php/ztp_gate.php endpoint can bypass authentication checks when the X-PAN-AUTHCHECK header is set to off. Upon exploitation, the server incorrectly processes the request and grants access to sensitive administrative features. Indicators of exploitation include specific status codes (200), session cookies (PHPSESSID), and responses containing terms like "Zero Touch Provisioning."

Exploiting this vulnerability can result in:

  • Full administrative access to the PAN-OS Management Web Interface.
  • Modification of critical firewall rules, leading to network compromise.
  • The ability to exploit privilege escalation vulnerabilities.
  • Disabling security features, leaving the network exposed to attacks.

S4E empowers organizations to stay ahead of vulnerabilities by providing comprehensive scanning and actionable insights. By detecting critical vulnerabilities like CVE-2024-0012, our platform enables proactive mitigation and reduces the risk of unauthorized access. Join today to leverage advanced scanners, detailed reports, and a collaborative platform to secure your digital assets effortlessly. Don't leave your network's security to chance—let S4E be your trusted partner.

References:

Solution Advice
  • Apply the latest security patches provided by Palo Alto Networks immediately.
  • Restrict access to the management web interface to trusted IP ranges.
  • Implement multi-factor authentication (MFA) for administrative access.
  • Monitor logs for signs of unauthorized access or unusual activity.
  • Conduct regular security audits to identify misconfigurations and vulnerabilities.

Get AI-powered remediation steps tailored to your asset.

Try AI Solutions →

Check your infrastructure.
Right now.

11,000+ scanners. Free to start. No credit card required.