Palo Alto Networks patches two firewall zero-days used in attacks

Share:

Palo Alto Networks has finally released security updates for two actively exploited zero-day vulnerabilities in its Next-Generation Firewalls (NGFW).

The first flaw, tracked as CVE-2024-0012, is an authentication bypass found in the PAN-OS management web interface that remote attackers can exploit to gain administrator privileges without requiring authentication or user interaction.

The second one (CVE-2024-9474) is a PAN-OS privilege escalation security flaw that allows malicious PAN-OS administrators to perform actions on the firewall with root privileges.

While CVE-2024-9474 was disclosed today, the company first warned customers on November 8 to restrict access to their next-generation firewalls because of a potential RCE flaw tagged last Friday as CVE-2024-0012.

“Palo Alto Networks observed threat activity that exploits this vulnerability against a limited number of management web interfaces that are exposed to internet traffic coming from outside the network,” the company warned today regarding both zero-days.

“Palo Alto Networks has actively monitored and worked with customers to identify and further minimize the very small number of PAN-OS devices with management web interfaces exposed to the Internet or other untrusted networks, ” it added in a separate report providing indicators of compromise for ongoing attacks targeting the flaws.

While the company says these zero-days impact only a “very small number” of firewalls, threat monitoring platform Shadowserver reported on Friday that it’s tracking more than 8,700 exposed PAN-OS management interfaces.

Palo Alto PAN-OS exposed management interfaces
Palo Alto PAN-OS exposed management interfaces (Shadowserver)

Macnica threat researcher Yutaka Sejiyama also told BleepingComputer that he found over 11,000 IP addresses running Palo Alto PAN-OS management interfaces exposed online using Shodan. According to Shodan, the most vulnerable devices are in the United States, followed by India, Mexico, Thailand, and Indonesia.

The U.S. cybersecurity agency added the CVE-2024-0012 and CVE-2024-9474 vulnerabilities to its Known Exploited Vulnerabilities Catalog and ordered federal agencies to patch their systems within three weeks by December 9.

In early November, CISA also warned of ongoing attacks exploiting a critical missing authentication vulnerability (CVE-2024-5910) in the Palo Alto Networks Expedition firewall configuration migration tool, a flaw patched in July that threat actors can remotely exploit it to reset application admin credentials on Internet-exposed Expedition servers.

“These types of vulnerabilities are frequent attack vectors for malicious cyber actors and pose significant risks to the federal enterprise,” CISA warns.

Sergiu Gatlan

Leave a Comment

Your email address will not be published. Required fields are marked *

loader-image
London, GB
12:48 pm, Jul 4, 2025
weather icon 24°C
L: 23° | H: 26°
overcast clouds
Humidity: 41 %
Pressure: 1026 mb
Wind: 9 mph WSW
Wind Gust: 0 mph
UV Index: 0
Precipitation: 0 mm
Clouds: 89%
Rain Chance: 0%
Visibility: 10 km
Sunrise: 4:49 am
Sunset: 9:19 pm
DailyHourly
Daily ForecastHourly Forecast
Today 10:00 pm
weather icon
23° | 26°°C 0 mm 0% 13 mph 42 % 1026 mb 0 mm/h
Tomorrow 10:00 pm
weather icon
14° | 19°°C 0.97 mm 97% 13 mph 90 % 1021 mb 0 mm/h
Sun Jul 06 10:00 pm
weather icon
16° | 20°°C 1 mm 100% 10 mph 89 % 1010 mb 0 mm/h
Mon Jul 07 10:00 pm
weather icon
14° | 23°°C 1 mm 100% 13 mph 77 % 1016 mb 0 mm/h
Tue Jul 08 10:00 pm
weather icon
13° | 25°°C 0 mm 0% 9 mph 77 % 1020 mb 0 mm/h
Today 1:00 pm
weather icon
24° | 24°°C 0 mm 0% 9 mph 42 % 1026 mb 0 mm/h
Today 4:00 pm
weather icon
24° | 25°°C 0 mm 0% 12 mph 37 % 1025 mb 0 mm/h
Today 7:00 pm
weather icon
23° | 23°°C 0 mm 0% 13 mph 31 % 1023 mb 0 mm/h
Today 10:00 pm
weather icon
20° | 20°°C 0 mm 0% 10 mph 40 % 1022 mb 0 mm/h
Tomorrow 1:00 am
weather icon
19° | 19°°C 0 mm 0% 10 mph 50 % 1021 mb 0 mm/h
Tomorrow 4:00 am
weather icon
17° | 17°°C 0 mm 0% 10 mph 52 % 1019 mb 0 mm/h
Tomorrow 7:00 am
weather icon
14° | 14°°C 0.97 mm 97% 9 mph 90 % 1018 mb 0 mm/h
Tomorrow 10:00 am
weather icon
17° | 17°°C 0.7 mm 70% 10 mph 82 % 1017 mb 0 mm/h
Name Price24H (%)
Bitcoin(BTC)
€92,668.34
-0.56%
Ethereum(ETH)
€2,169.87
-1.49%
Tether(USDT)
€0.85
0.00%
XRP(XRP)
€1.90
-2.56%
Solana(SOL)
€127.90
-2.58%
USDC(USDC)
€0.85
0.00%
Dogecoin(DOGE)
€0.141759
-3.79%
Shiba Inu(SHIB)
€0.000010
-2.90%
Pepe(PEPE)
€0.000008
-5.78%
Scroll to Top