PAN-OS management web interface
CVE-2024-0012: One header skips the login on the PAN-OS management interface
Sending X-PAN-AUTHCHECK set to off gave attackers admin access to exposed management interfaces. Chained with CVE-2024-9474 for root, it compromised about 2,000 firewalls within days of disclosure.
Published Updated
Affected and fixed versions
| Product / branch | Fixed in |
|---|---|
| PAN-OS 11.2 | 11.2.0-h1, 11.2.1-h1, 11.2.2-h2, 11.2.3-h3, 11.2.4-h1 or later |
| PAN-OS 11.1 | 11.1.0-h4, 11.1.1-h2, 11.1.2-h15, 11.1.3-h11, 11.1.4-h7, 11.1.5-h1 or later |
| PAN-OS 11.0 | 11.0.0-h4, 11.0.1-h5, 11.0.2-h5, 11.0.3-h13, 11.0.4-h6, 11.0.5-h2, 11.0.6-h1 or later (branch now end of life) |
| PAN-OS 10.2 | 10.2.0-h4, 10.2.1-h3, 10.2.2-h6, 10.2.3-h14, 10.2.4-h32, 10.2.5-h9, 10.2.6-h6, 10.2.7-h18, 10.2.8-h15, 10.2.9-h16, 10.2.10-h9, 10.2.11-h6, 10.2.12-h2 or later |
| PAN-OS 10.1 | Not affected (but see CVE-2024-9474) |
| Cloud NGFW, Prisma Access | Not affected |
Always confirm against the vendor advisory, which lists every fixed hotfix.
What it is
The PAN-OS management web interface uses Nginx in front of the PHP application. Nginx decides whether a request needs a login and tells the application through a header, X-PAN-AUTHCHECK.
On vulnerable versions, a client could simply send that header itself with the value off. The application trusted it and treated the request as coming from a logged-in administrator. No password, no MFA.
Admin access alone lets an attacker change the configuration. Attackers went further and chained it with CVE-2024-9474, a command injection that admins can use to run commands as root. Together they give full, unauthenticated control of the firewall. Once watchTowr published the details on 19 November 2024, the chain was trivial to reproduce, and mass exploitation followed.
Am I affected?
You’re at risk only if someone untrusted can reach the management web interface of a firewall or Panorama on an affected version (PAN-OS 10.2 to 11.2):
- The management port is reachable from the internet or an untrusted network.
- Or a management profile with HTTPS is attached to a dataplane interface in an untrusted zone, such as the outside interface or the one hosting GlobalProtect (management then usually answers on port 4443).
Palo Alto’s Customer Support Portal lists devices it saw with internet-facing management: Products > Assets > All Assets > Remediation Required.
PA-Series, VM-Series and CN-Series firewalls and Panorama (virtual and M-Series) are affected. Cloud NGFW and Prisma Access are not. GlobalProtect portals and gateways are not vulnerable themselves.
What to do
1. Get the management interface off untrusted networks. Restrict it to a management network or jump host, and remove management profiles from every outside interface. This also protects you from the next management-plane bug: CVE-2025-0108 appeared three months later in the same code.
2. Upgrade to a fixed hotfix. PAN-OS 11.0 is end of life now, so move to a supported branch rather than an 11.0 hotfix.
3. Know the limits of the IPS signatures. Threat IDs 95746, 95747, 95752, 95753, 95759 and 95763 detect this chain, but only for traffic the firewall can inspect. Management traffic to the dedicated MGT port isn’t inspected. The signatures only help when management access goes through a dataplane interface, with inbound decryption on. Don’t count on them for an exposed MGT port.
4. If the interface was exposed while unpatched, check for compromise (below) and follow the cleanup steps on the CVE-2024-9474 page if you find anything.
Detection
- Requests to the management interface carrying the
X-PAN-AUTHCHECKheader. Legitimate browsers never send it. This needs logs from something in front of the interface, such as a reverse proxy, WAF or packet capture. - Admin actions you can’t explain in the configuration and system logs: new administrators, commits, configuration exports, or logins from unfamiliar addresses, often anonymous VPN or VPS ranges.
- Files and processes that shouldn’t be there: PHP web shells in the web root (Unit 42 recovered an obfuscated shell that ran commands from a POST parameter), cryptocurrency miners, and open-source C2 implants were all reported.
- Unusual outbound connections from the firewall’s management IP.
- The hash and user agent below, and the IP addresses in Unit 42’s list.
Checking the file system needs a tech support file and Palo Alto’s help, since PAN-OS gives you no shell.
Indicators of compromise
Attacks came from many rotating VPN and VPS addresses, so Unit 42 keeps the IP list in a separate file. Use these to hunt in management logs and on suspect devices.
| Indicator | Type | Reported by |
|---|---|---|
| 3c5f9034c86cb1952aa5bb07b4f77ce7d8bb5cc9fe5c029a32c72adc7e814668 | SHA-256Obfuscated PHP web shell dropped on compromised firewalls | Unit 42 |
| Mozilla/5.0 (Windows NT 6.3; Trident/7.0; rv 11.0) like Gecko | User agentSeen in exploit attempts by multiple actors | Unit 42 |
Unit 42's full list of IP addresses for Operation Lunar Peek.
Sources
Page changelog
- Full analysis published.
KEV status, EPSS score and vendor data refreshed automatically, last on 10 Oct 2026.