CVE-2024-0012
CRITICAL KEV RANSOMWARE NUCLEIPalo Alto Networks PAN-OS 10.2 11.0 11.1 11.2 - Unauthenticated Authentication Bypass
Title source: llmExploitation Summary
CVE-2024-0012 is actively exploited and listed in the CISA Known Exploited Vulnerabilities (KEV) catalog, added November 18, 2024, with confirmed use in ransomware campaigns.
EIP tracks 12 public exploits from researchers including iSee857, watchtowrlabs, Sachinart, including a Metasploit module exploits/linux/http/panos_management_unauth_rce.
A Nuclei detection template is also available.
AI-analyzed exploit summary The repository contains functional exploit code for CVE-2026-22812, demonstrating a command execution vulnerability in OpenCode. The script sends a crafted JSON payload to the '/session/{id}/shell' endpoint to execute the 'id' command, confirming RCE if the response contains 'uid=' and 'gid='.
Description
An authentication bypass in Palo Alto Networks PAN-OS software enables an unauthenticated attacker with network access to the management web interface to gain PAN-OS administrator privileges to perform administrative actions, tamper with the configuration, or exploit other authenticated privilege escalation vulnerabilities like CVE-2024-9474 https://security.paloaltonetworks.com/CVE-2024-9474 . The risk of this issue is greatly reduced if you secure access to the management web interface by restricting access to only trusted internal IP addresses according to our recommended best practice deployment guidelines https://live.paloaltonetworks.com/t5/community-blogs/tips-amp-tricks-how-to-secure-the-management-access-of-your-palo/ba-p/464431 . This issue is applicable only to PAN-OS 10.2, PAN-OS 11.0, PAN-OS 11.1, and PAN-OS 11.2 software. Cloud NGFW and Prisma Access are not impacted by this vulnerability.
Exploits (12)
The repository contains functional exploit code for CVE-2026-22812, demonstrating a command execution vulnerability in OpenCode. The script sends a crafted JSON payload to the '/session/{id}/shell' endpoint to execute the 'id' command, confirming RCE if the response contains 'uid=' and 'gid='.
The repository contains a Nuclei template for detecting CVE-2024-0012, an authentication bypass vulnerability in Palo Alto PAN-OS. The template checks for a specific endpoint and response patterns to identify vulnerable systems but does not include exploit code.
This repository contains a functional exploit PoC for CVE-2024-0012, targeting Palo Alto PAN-OS. The exploit leverages command injection via a crafted session creation request and subsequent file access to verify execution.
This repository contains a functional exploit for CVE-2024-0012 (authentication bypass) and CVE-2024-9474 (command execution and privilege escalation) in Palo Alto PAN-OS. The exploit automates the process of bypassing authentication, uploading a reverse shell payload in chunks, and executing it on the target system.
This repository contains a functional GUI-based exploit for CVE-2024-0012, which involves an authentication bypass and command injection in Palo Alto PAN-OS. The exploit creates a session with crafted data, triggers command execution, and verifies the output.
This repository contains a functional exploit tool for CVE-2024-0012, targeting PAN-OS devices. It includes capabilities for credential dumping, command execution, and reverse shell establishment via command injection and authentication bypass techniques.
The repository contains a functional Python exploit for CVE-2024-0012, an authentication bypass vulnerability in Palo Alto Networks PAN-OS. The exploit leverages command injection via a crafted session creation request to achieve remote code execution (RCE) and can deploy a reverse shell.
The repository lacks actual exploit code and instead redirects users to an external link for more PoCs, which is a common tactic for suspicious or malicious repositories. The README provides minimal technical details about CVE-2024-0012 and focuses on external downloads.
This repository contains a Python script designed to detect the presence of CVE-2024-0012, an authentication bypass vulnerability in Palo Alto PAN-OS. The script sends HTTP requests with specific headers and checks for markers in the response to determine vulnerability status.
This PoC exploits a command injection vulnerability in Palo Alto PAN-OS by injecting a payload into the 'user' parameter during session creation, which writes system information to a file. The exploit then triggers execution and verifies the result by checking the created file.
This repository contains a functional exploit PoC for CVE-2024-0012, an authentication bypass vulnerability in Palo Alto Networks PAN-OS. The exploit leverages command injection via a crafted session creation request to achieve remote code execution.
This Metasploit module exploits an authentication bypass (CVE-2024-0012) and command injection (CVE-2024-9474) in Palo Alto Networks PAN-OS management interface to achieve unauthenticated remote code execution as root. It writes payload chunks to disk, amalgamates them, and executes the payload.
Nuclei Templates (1)
cpe:"cpe:2.3:o:paloaltonetworks:pan-os" || http.favicon.hash:"-631559155"
icon_hash="-631559155"
References (4)
Scores
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H