An authentication bypass in Palo Alto Networks PAN-OS software enables an unauthenticated attacker with network access to the management web interface to gain PAN-OS administrator privileges to perform administrative actions, tamper with the configuration, or exploit other authenticated privilege escalation vulnerabilities like CVE-2024-9474 https://security.paloaltonetworks.com/CVE-2024-9474 .
The risk of this issue is greatly reduced if you secure access to the management web interface by restricting access to only trusted internal IP addresses according to our recommended best practice deployment guidelines https://live.paloaltonetworks.com/t5/community-blogs/tips-amp-tricks-how-to-secure-the-management-access-of-your-palo/ba-p/464431 .
This issue is applicable only to PAN-OS 10.2, PAN-OS 11.0, PAN-OS 11.1, and PAN-OS 11.2 software.
Cloud NGFW and Prisma Access are not impacted by this vulnerability.
The product does not perform any authentication for functionality that requires a provable user identity or consumes a significant amount of resources.
| Name | Vendor | Start Version | End Version |
|---|---|---|---|
| Pan-os | Paloaltonetworks | 10.2.0 (including) | 10.2.0 (including) |
| Pan-os | Paloaltonetworks | 10.2.0-h1 (including) | 10.2.0-h1 (including) |
| Pan-os | Paloaltonetworks | 10.2.0-h2 (including) | 10.2.0-h2 (including) |
| Pan-os | Paloaltonetworks | 10.2.0-h3 (including) | 10.2.0-h3 (including) |
| Pan-os | Paloaltonetworks | 10.2.1 (including) | 10.2.1 (including) |
| Pan-os | Paloaltonetworks | 10.2.1-h1 (including) | 10.2.1-h1 (including) |
| Pan-os | Paloaltonetworks | 10.2.1-h2 (including) | 10.2.1-h2 (including) |
| Pan-os | Paloaltonetworks | 10.2.2 (including) | 10.2.2 (including) |
| Pan-os | Paloaltonetworks | 10.2.2-h1 (including) | 10.2.2-h1 (including) |
| Pan-os | Paloaltonetworks | 10.2.2-h2 (including) | 10.2.2-h2 (including) |
| Pan-os | Paloaltonetworks | 10.2.2-h4 (including) | 10.2.2-h4 (including) |
| Pan-os | Paloaltonetworks | 10.2.2-h5 (including) | 10.2.2-h5 (including) |
| Pan-os | Paloaltonetworks | 10.2.3 (including) | 10.2.3 (including) |
| Pan-os | Paloaltonetworks | 10.2.3-h11 (including) | 10.2.3-h11 (including) |
| Pan-os | Paloaltonetworks | 10.2.3-h12 (including) | 10.2.3-h12 (including) |
| Pan-os | Paloaltonetworks | 10.2.3-h13 (including) | 10.2.3-h13 (including) |
| Pan-os | Paloaltonetworks | 10.2.3-h2 (including) | 10.2.3-h2 (including) |
| Pan-os | Paloaltonetworks | 10.2.3-h4 (including) | 10.2.3-h4 (including) |
| Pan-os | Paloaltonetworks | 10.2.3-h9 (including) | 10.2.3-h9 (including) |
| Pan-os | Paloaltonetworks | 10.2.4 (including) | 10.2.4 (including) |
| Pan-os | Paloaltonetworks | 10.2.4-h10 (including) | 10.2.4-h10 (including) |
| Pan-os | Paloaltonetworks | 10.2.4-h16 (including) | 10.2.4-h16 (including) |
| Pan-os | Paloaltonetworks | 10.2.4-h2 (including) | 10.2.4-h2 (including) |
| Pan-os | Paloaltonetworks | 10.2.4-h3 (including) | 10.2.4-h3 (including) |
| Pan-os | Paloaltonetworks | 10.2.4-h4 (including) | 10.2.4-h4 (including) |
| Pan-os | Paloaltonetworks | 10.2.5 (including) | 10.2.5 (including) |
| Pan-os | Paloaltonetworks | 10.2.5-h1 (including) | 10.2.5-h1 (including) |
| Pan-os | Paloaltonetworks | 10.2.5-h4 (including) | 10.2.5-h4 (including) |
| Pan-os | Paloaltonetworks | 10.2.5-h6 (including) | 10.2.5-h6 (including) |
| Pan-os | Paloaltonetworks | 10.2.6 (including) | 10.2.6 (including) |
| Pan-os | Paloaltonetworks | 10.2.6-h1 (including) | 10.2.6-h1 (including) |
| Pan-os | Paloaltonetworks | 10.2.6-h3 (including) | 10.2.6-h3 (including) |
| Pan-os | Paloaltonetworks | 10.2.7 (including) | 10.2.7 (including) |
| Pan-os | Paloaltonetworks | 10.2.7-h1 (including) | 10.2.7-h1 (including) |
| Pan-os | Paloaltonetworks | 10.2.7-h12 (including) | 10.2.7-h12 (including) |
| Pan-os | Paloaltonetworks | 10.2.7-h16 (including) | 10.2.7-h16 (including) |
| Pan-os | Paloaltonetworks | 10.2.7-h3 (including) | 10.2.7-h3 (including) |
| Pan-os | Paloaltonetworks | 10.2.7-h6 (including) | 10.2.7-h6 (including) |
| Pan-os | Paloaltonetworks | 10.2.7-h8 (including) | 10.2.7-h8 (including) |
| Pan-os | Paloaltonetworks | 10.2.8 (including) | 10.2.8 (including) |
| Pan-os | Paloaltonetworks | 10.2.8-h10 (including) | 10.2.8-h10 (including) |
| Pan-os | Paloaltonetworks | 10.2.8-h13 (including) | 10.2.8-h13 (including) |
| Pan-os | Paloaltonetworks | 10.2.8-h3 (including) | 10.2.8-h3 (including) |
| Pan-os | Paloaltonetworks | 10.2.8-h4 (including) | 10.2.8-h4 (including) |
| Pan-os | Paloaltonetworks | 10.2.9 (including) | 10.2.9 (including) |
| Pan-os | Paloaltonetworks | 10.2.9-h1 (including) | 10.2.9-h1 (including) |
| Pan-os | Paloaltonetworks | 10.2.9-h11 (including) | 10.2.9-h11 (including) |
| Pan-os | Paloaltonetworks | 10.2.9-h14 (including) | 10.2.9-h14 (including) |
| Pan-os | Paloaltonetworks | 10.2.9-h9 (including) | 10.2.9-h9 (including) |
| Pan-os | Paloaltonetworks | 10.2.10 (including) | 10.2.10 (including) |
| Pan-os | Paloaltonetworks | 10.2.10-h2 (including) | 10.2.10-h2 (including) |
| Pan-os | Paloaltonetworks | 10.2.10-h3 (including) | 10.2.10-h3 (including) |
| Pan-os | Paloaltonetworks | 10.2.10-h4 (including) | 10.2.10-h4 (including) |
| Pan-os | Paloaltonetworks | 10.2.10-h5 (including) | 10.2.10-h5 (including) |
| Pan-os | Paloaltonetworks | 10.2.10-h7 (including) | 10.2.10-h7 (including) |
| Pan-os | Paloaltonetworks | 10.2.11 (including) | 10.2.11 (including) |
| Pan-os | Paloaltonetworks | 10.2.11-h1 (including) | 10.2.11-h1 (including) |
| Pan-os | Paloaltonetworks | 10.2.11-h2 (including) | 10.2.11-h2 (including) |
| Pan-os | Paloaltonetworks | 10.2.11-h3 (including) | 10.2.11-h3 (including) |
| Pan-os | Paloaltonetworks | 10.2.11-h4 (including) | 10.2.11-h4 (including) |
| Pan-os | Paloaltonetworks | 10.2.12 (including) | 10.2.12 (including) |
| Pan-os | Paloaltonetworks | 10.2.12-h1 (including) | 10.2.12-h1 (including) |
| Pan-os | Paloaltonetworks | 11.0.0 (including) | 11.0.0 (including) |
| Pan-os | Paloaltonetworks | 11.0.0-h1 (including) | 11.0.0-h1 (including) |
| Pan-os | Paloaltonetworks | 11.0.0-h2 (including) | 11.0.0-h2 (including) |
| Pan-os | Paloaltonetworks | 11.0.0-h3 (including) | 11.0.0-h3 (including) |
| Pan-os | Paloaltonetworks | 11.0.1 (including) | 11.0.1 (including) |
| Pan-os | Paloaltonetworks | 11.0.1-h2 (including) | 11.0.1-h2 (including) |
| Pan-os | Paloaltonetworks | 11.0.1-h3 (including) | 11.0.1-h3 (including) |
| Pan-os | Paloaltonetworks | 11.0.1-h4 (including) | 11.0.1-h4 (including) |
| Pan-os | Paloaltonetworks | 11.0.2 (including) | 11.0.2 (including) |
| Pan-os | Paloaltonetworks | 11.0.2-h1 (including) | 11.0.2-h1 (including) |
| Pan-os | Paloaltonetworks | 11.0.2-h2 (including) | 11.0.2-h2 (including) |
| Pan-os | Paloaltonetworks | 11.0.2-h3 (including) | 11.0.2-h3 (including) |
| Pan-os | Paloaltonetworks | 11.0.2-h4 (including) | 11.0.2-h4 (including) |
| Pan-os | Paloaltonetworks | 11.0.3 (including) | 11.0.3 (including) |
| Pan-os | Paloaltonetworks | 11.0.3-h1 (including) | 11.0.3-h1 (including) |
| Pan-os | Paloaltonetworks | 11.0.3-h10 (including) | 11.0.3-h10 (including) |
| Pan-os | Paloaltonetworks | 11.0.3-h12 (including) | 11.0.3-h12 (including) |
| Pan-os | Paloaltonetworks | 11.0.3-h3 (including) | 11.0.3-h3 (including) |
| Pan-os | Paloaltonetworks | 11.0.3-h5 (including) | 11.0.3-h5 (including) |
| Pan-os | Paloaltonetworks | 11.0.4 (including) | 11.0.4 (including) |
| Pan-os | Paloaltonetworks | 11.0.4-h1 (including) | 11.0.4-h1 (including) |
| Pan-os | Paloaltonetworks | 11.0.4-h2 (including) | 11.0.4-h2 (including) |
| Pan-os | Paloaltonetworks | 11.0.4-h5 (including) | 11.0.4-h5 (including) |
| Pan-os | Paloaltonetworks | 11.0.5 (including) | 11.0.5 (including) |
| Pan-os | Paloaltonetworks | 11.0.5-h1 (including) | 11.0.5-h1 (including) |
| Pan-os | Paloaltonetworks | 11.0.6 (including) | 11.0.6 (including) |
| Pan-os | Paloaltonetworks | 11.1.0 (including) | 11.1.0 (including) |
| Pan-os | Paloaltonetworks | 11.1.0-h1 (including) | 11.1.0-h1 (including) |
| Pan-os | Paloaltonetworks | 11.1.0-h2 (including) | 11.1.0-h2 (including) |
| Pan-os | Paloaltonetworks | 11.1.0-h3 (including) | 11.1.0-h3 (including) |
| Pan-os | Paloaltonetworks | 11.1.1 (including) | 11.1.1 (including) |
| Pan-os | Paloaltonetworks | 11.1.1-h1 (including) | 11.1.1-h1 (including) |
| Pan-os | Paloaltonetworks | 11.1.2 (including) | 11.1.2 (including) |
| Pan-os | Paloaltonetworks | 11.1.2-h1 (including) | 11.1.2-h1 (including) |
| Pan-os | Paloaltonetworks | 11.1.2-h12 (including) | 11.1.2-h12 (including) |
| Pan-os | Paloaltonetworks | 11.1.2-h14 (including) | 11.1.2-h14 (including) |
| Pan-os | Paloaltonetworks | 11.1.2-h3 (including) | 11.1.2-h3 (including) |
| Pan-os | Paloaltonetworks | 11.1.2-h4 (including) | 11.1.2-h4 (including) |
| Pan-os | Paloaltonetworks | 11.1.2-h9 (including) | 11.1.2-h9 (including) |
| Pan-os | Paloaltonetworks | 11.1.3 (including) | 11.1.3 (including) |
| Pan-os | Paloaltonetworks | 11.1.3-h1 (including) | 11.1.3-h1 (including) |
| Pan-os | Paloaltonetworks | 11.1.3-h10 (including) | 11.1.3-h10 (including) |
| Pan-os | Paloaltonetworks | 11.1.3-h2 (including) | 11.1.3-h2 (including) |
| Pan-os | Paloaltonetworks | 11.1.3-h4 (including) | 11.1.3-h4 (including) |
| Pan-os | Paloaltonetworks | 11.1.3-h6 (including) | 11.1.3-h6 (including) |
| Pan-os | Paloaltonetworks | 11.1.4 (including) | 11.1.4 (including) |
| Pan-os | Paloaltonetworks | 11.1.4-h1 (including) | 11.1.4-h1 (including) |
| Pan-os | Paloaltonetworks | 11.1.4-h4 (including) | 11.1.4-h4 (including) |
| Pan-os | Paloaltonetworks | 11.1.5 (including) | 11.1.5 (including) |
| Pan-os | Paloaltonetworks | 11.2.0 (including) | 11.2.0 (including) |
| Pan-os | Paloaltonetworks | 11.2.1 (including) | 11.2.1 (including) |
| Pan-os | Paloaltonetworks | 11.2.2 (including) | 11.2.2 (including) |
| Pan-os | Paloaltonetworks | 11.2.2-h1 (including) | 11.2.2-h1 (including) |
| Pan-os | Paloaltonetworks | 11.2.3 (including) | 11.2.3 (including) |
| Pan-os | Paloaltonetworks | 11.2.4 (including) | 11.2.4 (including) |