PAN-OS management web interface

CVE-2024-0012: One header skips the login on the PAN-OS management interface

Sending X-PAN-AUTHCHECK set to off gave attackers admin access to exposed management interfaces. Chained with CVE-2024-9474 for root, it compromised about 2,000 firewalls within days of disclosure.

Published Updated

ExploitedYes, in CISA KEVAdded 18 Nov 2024
Ransomware useKnownPer CISA
SeverityCRITICALCVSS 4.0 9.3
EPSS100%Chance of exploitation in 30 days
Public exploitYes
FixAvailable

Affected and fixed versions

Product / branchFixed in
PAN-OS 11.211.2.0-h1, 11.2.1-h1, 11.2.2-h2, 11.2.3-h3, 11.2.4-h1 or later
PAN-OS 11.111.1.0-h4, 11.1.1-h2, 11.1.2-h15, 11.1.3-h11, 11.1.4-h7, 11.1.5-h1 or later
PAN-OS 11.011.0.0-h4, 11.0.1-h5, 11.0.2-h5, 11.0.3-h13, 11.0.4-h6, 11.0.5-h2, 11.0.6-h1 or later (branch now end of life)
PAN-OS 10.210.2.0-h4, 10.2.1-h3, 10.2.2-h6, 10.2.3-h14, 10.2.4-h32, 10.2.5-h9, 10.2.6-h6, 10.2.7-h18, 10.2.8-h15, 10.2.9-h16, 10.2.10-h9, 10.2.11-h6, 10.2.12-h2 or later
PAN-OS 10.1Not affected (but see CVE-2024-9474)
Cloud NGFW, Prisma AccessNot affected

Always confirm against the vendor advisory, which lists every fixed hotfix.

What it is

The PAN-OS management web interface uses Nginx in front of the PHP application. Nginx decides whether a request needs a login and tells the application through a header, X-PAN-AUTHCHECK.

On vulnerable versions, a client could simply send that header itself with the value off. The application trusted it and treated the request as coming from a logged-in administrator. No password, no MFA.

Admin access alone lets an attacker change the configuration. Attackers went further and chained it with CVE-2024-9474, a command injection that admins can use to run commands as root. Together they give full, unauthenticated control of the firewall. Once watchTowr published the details on 19 November 2024, the chain was trivial to reproduce, and mass exploitation followed.

Am I affected?

You’re at risk only if someone untrusted can reach the management web interface of a firewall or Panorama on an affected version (PAN-OS 10.2 to 11.2):

  1. The management port is reachable from the internet or an untrusted network.
  2. Or a management profile with HTTPS is attached to a dataplane interface in an untrusted zone, such as the outside interface or the one hosting GlobalProtect (management then usually answers on port 4443).

Palo Alto’s Customer Support Portal lists devices it saw with internet-facing management: Products > Assets > All Assets > Remediation Required.

PA-Series, VM-Series and CN-Series firewalls and Panorama (virtual and M-Series) are affected. Cloud NGFW and Prisma Access are not. GlobalProtect portals and gateways are not vulnerable themselves.

What to do

1. Get the management interface off untrusted networks. Restrict it to a management network or jump host, and remove management profiles from every outside interface. This also protects you from the next management-plane bug: CVE-2025-0108 appeared three months later in the same code.

2. Upgrade to a fixed hotfix. PAN-OS 11.0 is end of life now, so move to a supported branch rather than an 11.0 hotfix.

3. Know the limits of the IPS signatures. Threat IDs 95746, 95747, 95752, 95753, 95759 and 95763 detect this chain, but only for traffic the firewall can inspect. Management traffic to the dedicated MGT port isn’t inspected. The signatures only help when management access goes through a dataplane interface, with inbound decryption on. Don’t count on them for an exposed MGT port.

4. If the interface was exposed while unpatched, check for compromise (below) and follow the cleanup steps on the CVE-2024-9474 page if you find anything.

Detection

  • Requests to the management interface carrying the X-PAN-AUTHCHECK header. Legitimate browsers never send it. This needs logs from something in front of the interface, such as a reverse proxy, WAF or packet capture.
  • Admin actions you can’t explain in the configuration and system logs: new administrators, commits, configuration exports, or logins from unfamiliar addresses, often anonymous VPN or VPS ranges.
  • Files and processes that shouldn’t be there: PHP web shells in the web root (Unit 42 recovered an obfuscated shell that ran commands from a POST parameter), cryptocurrency miners, and open-source C2 implants were all reported.
  • Unusual outbound connections from the firewall’s management IP.
  • The hash and user agent below, and the IP addresses in Unit 42’s list.

Checking the file system needs a tech support file and Palo Alto’s help, since PAN-OS gives you no shell.

Indicators of compromise

Attacks came from many rotating VPN and VPS addresses, so Unit 42 keeps the IP list in a separate file. Use these to hunt in management logs and on suspect devices.

IndicatorTypeReported by
3c5f9034c86cb1952aa5bb07b4f77ce7d8bb5cc9fe5c029a32c72adc7e814668SHA-256Obfuscated PHP web shell dropped on compromised firewallsUnit 42
Mozilla/5.0 (Windows NT 6.3; Trident/7.0; rv 11.0) like GeckoUser agentSeen in exploit attempts by multiple actorsUnit 42

Unit 42's full list of IP addresses for Operation Lunar Peek.

Sources

Page changelog

  • Full analysis published.

KEV status, EPSS score and vendor data refreshed automatically, last on 10 Oct 2026.

Get alerts

A notification when we publish a new analysis or a covered vendor gets a new actively exploited CVE. No account, no email.