
⚠ HIGH PRIORITY — CISA KEV. CVE-2024-0012 is a privilege escalation in Palo Alto PAN-OS management plane. Chained with CVE-2024-9474 auth bypass, attackers gain root on firewalls and modify security policies.
Affected PAN-OS
- PAN-OS 10.2 before 10.2.12-h2
- PAN-OS 11.0 before 11.0.6-h1
- PAN-OS 11.1 before 11.1.5-h1
- Management interface reachable from untrusted networks
Verify version
> show system info | match sw-version
> show system setting managementPatching Method
- Download fixed PAN-OS image from Palo Alto support portal matching your train.
- Schedule maintenance — firewall may fail over in HA pair.
- Install via Device → Software → Check Now → Download and Install.
- Reboot when prompted; confirm HA sync after patch.
- Export running config and diff against pre-patch baseline for rogue rules/users.
- Also patch CVE-2024-9474 if not already on fixed management-auth build.
> show system info | match sw-version
> show config diff
> show admins allWorkaround
- Never expose PAN-OS management to internet
- Restrict mgmt VLAN to jump host IP only
- Enable MFA on all admin accounts immediately