Description
Management Interface of PAN-OS contains an authentication vulnerability that could allow an unauthenticated attacker to access restricted functionality and exploit the RCE vulnerability, CVE-2024-9474, to compromise the system.
Remediation
Upgrade to the latest version of Palo Alto PAN-OS.
References
CVE-2024-0012 PAN-OS: Authentication Bypass in the Management Web Interface (PAN-SA-2024-0015)
CVE-2024-9474 PAN-OS: Privilege Escalation (PE) Vulnerability in the Web Management Interface
Pots and Pans, AKA an SSLVPN - Palo Alto PAN-OS CVE-2024-0012 and CVE-2024-9474
Related Vulnerabilities
Ampache Cross-Site Request Forgery (CSRF) Vulnerability (CVE-2024-51488)
Oracle Application Server Other Vulnerability (CVE-2002-0655)
LimeSurvey Exposure of Sensitive Information to an Unauthorized Actor Vulnerability (CVE-2018-7556)
Oracle Sun GlassFish/Java System Application Server Remote Authentication Bypass Vulnerability