CVE-2024-0012 is a critical improper authentication vulnerability in the management web interface of Palo Alto Networks PAN-OS. It affects PAN-OS 10.2, 11.0, 11.1, and 11.2 prior to vendor-fixed releases. Successful exploitation allows an unauthenticated attacker with network access to the management interface to bypass authentication and obtain PAN-OS administrator privileges. With administrator access, an attacker can perform administrative actions, alter device configuration, and leverage additional authenticated flaws such as CVE-2024-9474 to escalate further to root-level command execution. The vulnerability has been observed in active exploitation, particularly against internet-exposed management interfaces.
Mallory correlates every CVE against your assets, your vendors, and active adversary campaigns. Know which vulnerabilities matter for you, not just which ones are loud.
What it means. What to do now. Patch path, mitigations, and the assume-compromise checklist.
What an attacker gets, and what they’ve been doing with it.
If you can’t patch tonight, do this now.
Patch, then assume compromise.
8 valid exploits after Mallory filtered fakes, detection scripts, and README-only repos (2 hidden).
This repository is a small standalone exploit PoC with two files: a README describing the PAN-OS vulnerability chain and a single Python entry-point script, exploit.py. The script targets Palo Alto Networks PAN-OS management interfaces over HTTPS and chains CVE-2024-0012 (authentication bypass) with CVE-2024-9474 (privilege escalation via PHP session path traversal) to achieve unauthenticated root-level RCE. Repository structure is minimal and purpose-built: README.md documents affected versions, exploitation logic, and mitigation guidance; exploit.py implements the attack flow. The Python code uses requests, disables TLS warnings for self-signed certificates, parses CLI arguments, and executes in two stages. Stage 1 iterates through a hardcoded list of candidate REST API paths such as /php/../restapi/10.2/ and /restapi/10.2/ to obtain an authenticated session context by probing for successful HTTP responses or redirects. Stage 2 builds a PHP payload of the form <?php system("<command>"); ?>, then abuses the session handler endpoint /php/utils/session_handler.php by supplying a traversal-based session identifier like ../../php/shell_xxxxxx.php, intending to write the payload into a web-accessible PHP location. The exploit’s main capability is arbitrary command execution as root via an uploaded PHP webshell. It supports a user-supplied command, optional custom shell filename, configurable target/port, optional SSL verification disablement, and an optional interactive shell mode after successful upload. Based on the available code and README, this is a real exploit rather than a detector, and it is best classified as OPERATIONAL: it contains a working hardcoded payload and end-to-end exploitation logic, but it is not part of a larger exploitation framework.
This repository contains a single main exploit tool, PanOsExploitMultitool.py, written in Python. The tool targets Palo Alto Networks PAN-OS devices vulnerable to CVE-2024-0012 and CVE-2024-9474, providing exploitation and post-exploitation capabilities. The script supports several commands: - 'check': Tests if a target is vulnerable. - 'shell': Exploits the target to obtain a reverse shell by chunking and writing a base64-encoded bash shell payload to a writable directory, then executing it to connect back to the attacker's listener. - 'dump': Retrieves and decrypts credentials from the target's configuration files using a known AES master key, and can also extract the full running configuration. - 'local': Decrypts credentials from a local XML config file, useful for offline analysis. - 'decrypt': Interactively decrypts encrypted credential strings using the public master key. The tool interacts with the PAN-OS management interface over HTTPS (default port 443), and uses file paths such as /var/tmp/ and /opt/pancfg/mgmt/saved-configs/ on the target device. It is operational and provides real exploitation and credential extraction capabilities, not just detection. The repository includes a README with detailed usage instructions and references, a requirements.txt for dependencies, and an Apache 2.0 license.
This repository contains a single Metasploit module (panos_management_unauth_rce.rb) that exploits two vulnerabilities (CVE-2024-0012 and CVE-2024-9474) in the Palo Alto Networks PAN-OS management web interface. The exploit leverages an authentication bypass and a command injection to achieve unauthenticated remote code execution as root on affected PAN-OS versions (10.2, 11.0, 11.1, 11.2 up to specified patch levels). The module is highly weaponized, supporting arbitrary command or shell payloads (including Meterpreter and reverse shells), which are delivered in chunks due to command length restrictions. The exploit interacts with specific web endpoints (notably /php/utils/createRemoteAppwebSession.php and /index.php/.js.map) and writes payloads to writable directories on the target. The code is structured as a standard Metasploit exploit module, with clear separation of check and exploit routines, and is intended for use within the Metasploit framework.
This repository contains a Python GUI exploit tool targeting Palo Alto Networks PAN-OS vulnerabilities CVE-2024-0012 (authentication bypass) and CVE-2024-9474 (authenticated command injection) in the management web interface. The main file, 'cve-2024-0012-gui.py', provides a PyQt5-based interface allowing the user to specify a target URL, command to execute, SSL verification, and request timeout. The exploit works by sending a crafted POST request to '/php/utils/createRemoteAppwebSession.php/cve.js.map' with a malicious 'user' parameter that injects a shell command. The output of the command is written to '/var/appweb/htdocs/unauth/cve.php', which is then accessed via HTTP to verify execution and retrieve the result. The tool automates the full exploit chain, including session creation, command execution, and output retrieval, and is operational with customizable command input. The README provides context and credits but no additional code.
This repository contains a Python proof-of-concept exploit for CVE-2024-0012 (authentication bypass) and CVE-2024-9474 (command execution) affecting Palo Alto Networks PAN-OS. The main file, 'CVE-2024-0012_CVE-2024-9474_Exploit_Palo_Alto_PAN-OS_PoC.py', automates the exploitation process: it first checks if the target is vulnerable, extracts a PHP session ID, generates a double-base64-encoded bash reverse shell payload, and uploads it in chunks to the target using a vulnerable PHP endpoint. The script then reconstructs and decodes the payload on the target, writes it to a shell script, and executes it, resulting in a reverse shell connection to the attacker's listener. The exploit leverages specific HTTP endpoints on the target PAN-OS device and uses temporary files for payload assembly. The repository also includes a detailed README with usage instructions, vulnerability descriptions, and references. The exploit is operational and provides a working reverse shell if the target is vulnerable and properly configured.
This repository contains a Python exploit script (cve-2024-0012.py) targeting CVE-2024-0012, an authentication bypass vulnerability in Palo Alto Networks PAN-OS. The exploit allows an unauthenticated attacker with network access to the management web interface to execute arbitrary commands as an administrator. The script supports both arbitrary command execution and deploying a reverse shell to the attacker's machine. It works by sending crafted HTTP requests to specific endpoints on the target PAN-OS device, exploiting the authentication bypass to inject commands. The repository consists of a single exploit script and a README with usage instructions. The exploit is operational, providing real command execution and reverse shell capabilities, and is not part of a larger framework.
This repository contains a Python proof-of-concept exploit for CVE-2024-0012, targeting Palo Alto Networks PAN-OS. The exploit leverages a command injection vulnerability via a crafted POST request to a specific endpoint. The payload executes 'netstat -ano' on the target and writes the output to a web-accessible file, which is then retrieved to confirm successful code execution. The script supports both single and batch URL testing via command-line arguments. The main code file is 'CVE-2024-0012', and the repository also includes a README with usage instructions. The exploit demonstrates operational maturity, as it provides a working payload and automates the exploitation process, but does not include advanced features such as a customizable shell. The attack vector is network-based, requiring HTTP access to the target endpoints. Several fingerprintable endpoints and a file path are hardcoded in the exploit, which are indicative of the targeted application structure.
This repository contains a Python proof-of-concept exploit for CVE-2024-0012, a command injection vulnerability in Palo Alto Networks PAN-OS. The repository consists of a README.md with usage instructions and a single exploit script (cve-2024-0012-pan-os-poc.py). The script targets a PAN-OS device by sending a crafted POST request to '/php/utils/createRemoteAppwebSession.php/watchTowr.js.map' with a command injection payload that writes the output of 'uname -a' to '/var/appweb/htdocs/unauth/watchTowr.php'. It then triggers the execution and verifies exploitation by retrieving the output file via '/unauth/watchTowr.php'. The exploit demonstrates successful command execution but does not provide a weaponized or customizable payload. The main attack vector is network-based, requiring HTTP(S) access to the target device. The endpoints used in the exploit are clearly defined in the script.
Products and vendors Mallory has correlated with this vulnerability. Open in Mallory to drill down to specific CPE configurations and version ranges.
Vendor-confirmed product mapping. Mallory continuously reconciles this list against your asset inventory.
26 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
A critical vulnerability referenced as part of the Operation Lunar Peek attack chain; it was bypassed by CVE-2024-9474 in attacks that led to compromise of Palo Alto Networks firewalls.
A Palo Alto Networks vulnerability that CISA KEV’s knownRansomwareCampaignUse field silently flipped to Known during 2025 (evidence of ransomware campaign use).
An authentication bypass vulnerability in the PAN-OS management interface of Palo Alto Networks Next-Generation Firewalls. It can be abused by manipulating a Palo Alto authentication header and, when chained with CVE-2024-9474, enables unauthenticated root-level command execution on affected firewalls.
A zero-day vulnerability in Palo Alto products with proof-of-concept exploits released.
Query your assets running an affected version, and investigate the blast radius.
Every observed campaign linking this CVE to a named adversary.
Malware families riding this exploit, with evidence and IOCs.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Cross-references every affected SKU, including bundled OEM variants.
Community discussion across Reddit, Mastodon, and other social sources.