Exploited Known exploited (KEV) Ransomware use CVE-2024-0012

PAN-OS management interface authentication bypass (CVE-2024-0012) — the required action says not to expose management to untrusted networks

Palo Alto Networks PAN-OS Added to KEV Nov 18, 2024 Federal remediation due 2024-12-09

An authentication bypass vulnerability in the management interface of Palo Alto Networks PAN-OS. Beyond applying updates, the required action states expressly that management interfaces should not be exposed to untrusted networks including the internet.

Key facts

  • CVE IDCVE-2024-0012
  • Affected (vendor / product)Palo Alto Networks PAN-OS
  • CWECWE-306
  • ExploitationListed in CISA KEV (exploitation confirmed); also confirmed used in ransomware
  • Remediation due2024-12-09 (U.S. federal civilian agencies, BOD 22-01)

Key points

  • The affected product is Palo Alto Networks PAN-OS, classified as CWE-306, missing authentication for critical function.
  • The bypass concerns the web-based management interface of products including firewalls and VPN concentrators.
  • The required action adds, beyond applying updates, that management interfaces should not be exposed to untrusted networks.
  • Where a boundary device management plane is reached, the premise that it decides what passes is itself affected.
  • Added November 18, 2024 with a due date of December 9, 21 days later; use in ransomware campaigns is known.

1Missing, rather than improper

Flaws around authentication divide between those where checking is done improperly and those where checking is absent. This class covers the second: authentication missing for a critical function.

Where authentication is improperWhere authentication is missing (this class)
A check occurs but its method has a problemNo check exists for the critical function
It may be circumvented under conditionsIt may be used by whoever can reach it
Strengthening the check can address itIntroducing a check is what is needed

Here the bypass concerns a management interface — the entrance through which a device configuration is changed. Reaching it puts the behaviour of the device itself within reach.

2The required action includes configuration

  1. 1The usual required actionApply mitigations per vendor instructions
  2. 2Also usualDiscontinue use of the product where mitigations are unavailable
  3. 3Added hereDo not expose management interfaces to untrusted networks
  4. 4What that meansNot only updating, but changing how the device is placed

In most catalog entries the required action reduces to applying updates or discontinuing use. Here a configuration instruction is added: management interfaces should not be exposed to untrusted networks including the internet. It reads as stating a design premise apart from fixing any single vulnerability.

3Devices placed at a boundary

Products coveredFirewalls and VPN concentratorsWith web-based management interfaces
Added to the catalogNovember 18, 2024Due date December 9, 21 days later
Use in ransomware campaignsKnownReaching the management plane can be the origin of the effect

The products covered include firewalls and VPN concentrators — devices placed at a boundary, deciding what traffic passes and what does not. A state in which their configuration can be altered undoes the premise of the boundary itself. This site covers vulnerabilities in other devices at the same position, showing how repeatedly they appear.

4Separating traffic from management

Keeping management interfaces off untrusted networks corresponds to separating the path business traffic takes from the path used to manage a device. Separated, the range from which the management plane can be reached is limited, and so is the effect of any single vulnerability. That the point is stated as a required action also indicates that unseparated configurations exist in practice.

Why it matters

Separating the path business traffic takes from the path used to manage devices limits where the management plane can be reached from, and limits the effect of any single vulnerability. That it is stated as a required action indicates unseparated configurations exist.

FAQ

How do missing and improper authentication differ?
Improper means a check occurs but its method has a problem; missing means no check exists for the critical function at all.
Why include a configuration instruction?
It reads as stating a design premise separate from fixing a single vulnerability: that a management plane should not sit where it can be reached from outside.

Sources (primary)

This article is an independent organization based on the U.S. official data below. Always verify the exact, latest details and applicability with the official and vendor sources.

#Security#CISA#KEV#Authentication bypass#Network devices
Disclaimer: This site independently summarizes and classifies information based on official data sources. Always verify the latest and accurate information with the official sources. Content on finance, health, legal, and security is information, not advice. This site is not an official website of the U.S. government.