CVE-2024-0009
PAN-OS vulnerability analysis and mitigation

Overview

An improper verification vulnerability (CVE-2024-0009) was discovered in the GlobalProtect gateway feature of Palo Alto Networks PAN-OS software. The vulnerability was disclosed on February 14, 2024, and affects PAN-OS versions 10.2.0 through 10.2.4 and version 11.0.0. This security flaw enables malicious users with stolen credentials to establish VPN connections from unauthorized IP addresses (Palo Alto Advisory).

Technical details

The vulnerability has been assigned a CVSS v3.1 base score of 6.3 (Medium) with the vector string CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L. It is classified under CWE-940 (Improper Verification of Source of a Communication Channel) and CWE-346 (Origin Validation Error). The issue specifically affects PAN-OS firewall configurations with GlobalProtect gateway enabled, which can be verified through the firewall web interface under Network > GlobalProtect > Gateways (NVD, Palo Alto Advisory).

Impact

The vulnerability allows attackers with compromised credentials to bypass IP-based access controls and establish unauthorized VPN connections to the affected systems. This could potentially lead to unauthorized access to network resources and compromise of security controls (Palo Alto Advisory).

Mitigation and workarounds

The vulnerability has been fixed in PAN-OS versions 10.2.4, 11.0.1, and all later PAN-OS releases. Organizations running affected versions should upgrade to the patched versions. The issue only affects systems with GlobalProtect gateway enabled (Palo Alto Advisory).

Additional resources


SourceThis report was generated using AI

Related PAN-OS vulnerabilities:

CVE ID

Severity

Score

Technologies

Component name

CISA KEV exploit

Has fix

Published date

CVE-2025-4231HIGH8.6
  • PAN-OSPAN-OS
  • cpe:2.3:o:paloaltonetworks:pan-os
NoYesJun 13, 2025
CVE-2025-4230HIGH8.4
  • PAN-OSPAN-OS
  • cpe:2.3:o:paloaltonetworks:pan-os
NoYesJun 13, 2025
CVE-2025-4615HIGH7
  • PAN-OSPAN-OS
  • cpe:2.3:o:paloaltonetworks:pan-os
NoYesOct 09, 2025
CVE-2025-4614MEDIUM4.8
  • PAN-OSPAN-OS
  • cpe:2.3:o:paloaltonetworks:pan-os
NoYesOct 09, 2025
CVE-2025-0137MEDIUM4.8
  • PAN-OSPAN-OS
  • cpe:2.3:o:paloaltonetworks:pan-os
NoYesMay 14, 2025

Free Vulnerability Assessment

Benchmark your Cloud Security Posture

Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.

Request assessment

Get a personalized demo

Ready to see Wiz in action?

"Best User Experience I have ever seen, provides full visibility to cloud workloads."
David EstlickCISO
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
Adam FletcherChief Security Officer
"We know that if Wiz identifies something as critical, it actually is."
Greg PoniatowskiHead of Threat and Vulnerability Management