Palo Alto Networks patches two firewall zero-days used in attacks

Teilen:

Palo Alto Networks has finally released security updates for two actively exploited zero-day vulnerabilities in its Next-Generation Firewalls (NGFW).

The first flaw, tracked as CVE-2024-0012, is an authentication bypass found in the PAN-OS management web interface that remote attackers can exploit to gain administrator privileges without requiring authentication or user interaction.

The second one (CVE-2024-9474) is a PAN-OS privilege escalation security flaw that allows malicious PAN-OS administrators to perform actions on the firewall with root privileges.

While CVE-2024-9474 was disclosed today, the company first warned customers on November 8 to restrict access to their next-generation firewalls because of a potential RCE flaw tagged last Friday as CVE-2024-0012.

“Palo Alto Networks observed threat activity that exploits this vulnerability against a limited number of management web interfaces that are exposed to internet traffic coming from outside the network,” the company warned today regarding both zero-days.

“Palo Alto Networks has actively monitored and worked with customers to identify and further minimize the very small number of PAN-OS devices with management web interfaces exposed to the Internet or other untrusted networks, ” it added in a separate report providing indicators of compromise for ongoing attacks targeting the flaws.

While the company says these zero-days impact only a “very small number” of firewalls, threat monitoring platform Shadowserver reported on Friday that it’s tracking more than 8,700 exposed PAN-OS management interfaces.

Palo Alto PAN-OS exposed management interfaces
Palo Alto PAN-OS exposed management interfaces (Shadowserver)

Macnica threat researcher Yutaka Sejiyama also told BleepingComputer that he found over 11,000 IP addresses running Palo Alto PAN-OS management interfaces exposed online using Shodan. According to Shodan, the most vulnerable devices are in the United States, followed by India, Mexico, Thailand, and Indonesia.

The U.S. cybersecurity agency added the CVE-2024-0012 and CVE-2024-9474 vulnerabilities to its Known Exploited Vulnerabilities Catalog and ordered federal agencies to patch their systems within three weeks by December 9.

In early November, CISA also warned of ongoing attacks exploiting a critical missing authentication vulnerability (CVE-2024-5910) in the Palo Alto Networks Expedition firewall configuration migration tool, a flaw patched in July that threat actors can remotely exploit it to reset application admin credentials on Internet-exposed Expedition servers.

“These types of vulnerabilities are frequent attack vectors for malicious cyber actors and pose significant risks to the federal enterprise,” CISA warns.

Sergiu Gatlan

Kommentar verfassen

Deine E-Mail-Adresse wird nicht veröffentlicht. Erforderliche Felder sind mit * markiert

lade-bild
London, GB
2:39 am, Feb. 4, 2025
Wetter-Symbol 7°C
L: 6° | H: 7°
wenige Wolken
Luftfeuchtigkeit: 91 %
Druck: 1023 mb
Wind: 7 mph SSW
Windböe: 0 mph
UV-Index: 0
Niederschlag: 0 mm
Wolken: 20%
Regen Chance: 0%
Sichtbarkeit: 10 km
Sonnenaufgang: 7:34 am
Sonnenuntergang: 4:54 pm
TäglichStündlich
Tägliche VorhersageStündliche Vorhersage
Today 9:00 pm
Wetter-Symbol
6° | 7°°C 0.2 mm 20% 15 mph 93 % 1026 mb 0 mm/h
Tomorrow 9:00 pm
Wetter-Symbol
4° | 8°°C 0 mm 0% 9 mph 86 % 1045 mb 0 mm/h
Do. Feb. 06 9:00 pm
Wetter-Symbol
2° | 8°°C 0 mm 0% 9 mph 86 % 1046 mb 0 mm/h
Fr. Feb. 07 9:00 pm
Wetter-Symbol
2° | 6°°C 0 mm 0% 12 mph 92 % 1041 mb 0 mm/h
Sa. Feb. 08 9:00 pm
Wetter-Symbol
1° | 4°°C 0.35 mm 35% 10 mph 89 % 1030 mb 0.15 mm/h
Today 3:00 am
Wetter-Symbol
5° | 7°°C 0 mm 0% 6 mph 91 % 1023 mb 0 mm/h
Today 6:00 am
Wetter-Symbol
6° | 6°°C 0 mm 0% 9 mph 93 % 1023 mb 0 mm/h
Today 9:00 am
Wetter-Symbol
7° | 7°°C 0 mm 0% 11 mph 91 % 1022 mb 0 mm/h
Today 12:00 pm
Wetter-Symbol
10° | 10°°C 0 mm 0% 13 mph 75 % 1022 mb 0 mm/h
Today 3:00 pm
Wetter-Symbol
9° | 9°°C 0 mm 0% 15 mph 76 % 1021 mb 0 mm/h
Today 6:00 pm
Wetter-Symbol
10° | 10°°C 0.2 mm 20% 12 mph 88 % 1022 mb 0 mm/h
Today 9:00 pm
Wetter-Symbol
8° | 8°°C 0.2 mm 20% 10 mph 74 % 1026 mb 0 mm/h
Tomorrow 12:00 am
Wetter-Symbol
6° | 6°°C 0 mm 0% 9 mph 82 % 1030 mb 0 mm/h
Name Preis24H (%)
Bitcoin(BTC)
€97,791.65
8.15%
Ethereum(ETH)
€2,747.45
15.20%
XRP(XRP)
€2.67
31.29%
Fesseln(USDT)
€0.97
0.03%
Solana(SOL)
€211.40
17.20%
USDC(USDC)
€0.97
0.00%
Dogecoin(DOGE)
€0.275336
24.30%
Shiba Inu(SHIB)
€0.000015
26.23%
Pepe(PEPE)
€0.000011
20.64%
Nach oben scrollen