Will Dormann on Nostr: How does one prove that they're authenticated to the PAN-OS security product, one ...
How does one prove that they're authenticated to the PAN-OS security product, one might wonder.
Simple.
You provide a "X-PAN-AUTHCHECK: off" HTTP header.
CVE-2024-0012, folks.
https://labs.watchtowr.com/pots-and-pans-aka-an-sslvpn-palo-alto-pan-os-cve-2024-0012-and-cve-2024-9474/
Simple.
You provide a "X-PAN-AUTHCHECK: off" HTTP header.
CVE-2024-0012, folks.
https://labs.watchtowr.com/pots-and-pans-aka-an-sslvpn-palo-alto-pan-os-cve-2024-0012-and-cve-2024-9474/
![](https://media.infosec.exchange/infosec.exchange/media_attachments/files/113/509/876/394/322/266/original/6ac22bdd57959247.png)