CVE-2024-0009: Palo Alto Networks PAN-OS

Medium severity, CVSS 6.3. EPSS: 0.2% chance of exploitation in the next 30 days.

An improper verification vulnerability in the GlobalProtect gateway feature of Palo Alto Networks PAN-OS software enables a malicious user with stolen credentials to establish a VPN connection from an unauthorized IP address.

Affected products

  • Palo Alto Networks PAN-OS: version 11.0.0 only; from 10.2.0, before 10.2.4 (fixed in 10.2.4)

Published 2024-02-14. Last modified 2026-06-17.