boxscore/security
CVE · referencelatest edition

Reference page — cumulative record through Wednesday, August 19, 2026 UTC. Reference pages update as the archive grows; only dated daily editions are immutable pages of record.

CVE-2024-0012CRITICAL
Palo Alto Networks Cloud NGFW — PAN-OS: Authentication Bypass in the Management Web Interface (PAN-SA-2024-0015)
  AV  AC  AT  PR  UI  VC  VI  VA   CVSS    EPSS    %ile   KEV
   N   L   N   N   N   H   H   H    9.3   .9970   100.0   YES
AFFECTED
  Product        Versions     Fixed
  Cloud NGFW     unspecified  All
  PAN-OS         11.2.0 –     11.2.4-h1
  Prisma Access  unspecified  All
TIMELINE
  Nov 9   Reserved by palo_alto
  Nov 18  Added to CISA KEV, remediation due 2024-12-09
  Nov 18  Published (CNA: palo_alto)
  Aug 3   PATCH SHIPPED — CVE-2024-0012 (Palo Alto Networks Cloud NGFW). Fixed in Cloud NGFW All.
  Aug 4   EXPLOIT PUBLISHED — CVE-2024-0012 (Palo Alto Networks Cloud NGFW). Public exploit reference added.
CWE-306 · CNA: palo_alto · CVSS v4.0 · 4 references · NVD status: Analyzed · KEV due December 9, 2024

Description

An authentication bypass in Palo Alto Networks PAN-OS software enables an unauthenticated attacker with network access to the management web interface to gain PAN-OS administrator privileges to perform administrative actions, tamper with the configuration, or exploit other authenticated privilege escalation vulnerabilities like CVE-2024-9474 https://security.paloaltonetworks.com/CVE-2024-9474 . The risk of this issue is greatly reduced if you secure access to the management web interface by restricting access to only trusted internal IP addresses according to our recommended  best practice deployment guidelines https://live.paloaltonetworks.com/t5/community-blogs/tips-amp-tricks-how-to-secure-the-management-access-of-your-palo/ba-p/464431 . This issue is applicable only to PAN-OS 10.2, PAN-OS 11.0, PAN-OS 11.1, and PAN-OS 11.2 software. Cloud NGFW and Prisma Access are not impacted by this vulnerability.

Lifecycle

Complete event history — 5 events, chronological
DateEventDetail
November 9, 2023ReservedReserved by palo_alto
November 18, 2024KEV ADDEDAdded to CISA KEV, remediation due 2024-12-09
November 18, 2024PublishedPublished (CNA: palo_alto)
August 3, 2026PATCH SHIPPEDPATCH SHIPPED — CVE-2024-0012 (Palo Alto Networks Cloud NGFW). Fixed in Cloud NGFW All.
August 4, 2026EXPLOIT PUBLISHEDEXPLOIT PUBLISHED — CVE-2024-0012 (Palo Alto Networks Cloud NGFW). Public exploit reference added.

Affected

Affected products and packages — 3 rows
VendorProduct / PackageEcosystemVersion introducedFixed
Palo Alto NetworksCloud NGFWAll
Palo Alto NetworksPAN-OS11.2.011.2.4-h1
Palo Alto NetworksPrisma AccessAll

Weaknesses

CWE-306

References (4)

Related

Authoritative record: CVE-2024-0012 at cve.org

Vendors: palo alto networks

Weaknesses: CWE-306

About this page

This is a reference page, not a dated page of record. It assembles the complete lifecycle of CVE-2024-0012 from the CVE Program record, NVD enrichment, the CISA KEV catalog, EPSS, and OSV advisories. The box score's numbers (CVSS, EPSS, KEV status) are current as of Wednesday, August 19, 2026 UTC and are re-derived as the archive grows; only dated daily editions are immutable pages of record. The authoritative source for this identifier is cve.org.