logo

Follow-Up: Arctic Wolf Observes Ongoing Exploitation of Critical Palo Alto Networks Vulnerability CVE-2024-0012 Chained with CVE-2024-9474

ID: 6e3c48d9-1799-5770-899c-a1883989172b

STIX ID: report--6e3c48d9-1799-5770-899c-a1883989172b

Feed Name: Arctic Wolf

Threat Score
80/100

Date Published: 2024-11-20

Date Updated: 2026-07-25

Author: Andres Ramos

...
...

Arctic Wolf reports active exploitation of PAN-OS vulnerabilities CVE-2024-0012 and CVE-2024-9474; when chained, these allow an unauthenticated attacker with access to the management web interface to gain administrator/root privileges. Exploitation has been observed in customer environments with attempts to transfer tools and exfiltrate configuration files; a public PoC was released on 2024-11-19, increasing the risk. The advisory lists affected PAN-OS and Panorama/WildFire versions, provides fixed versions to upgrade to, and recommends removing devices from internet exposure, restricting management access (e.g., jump boxes, IP whitelists), and contacting Palo Alto for Enhanced Factory Reset if compromise is confirmed.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.