CISA warnt vor kritischem Fehler in Palo Alto Networks, der bei Angriffen ausgenutzt wird

Teilen:

Today, CISA warned that attackers are exploiting a critical missing authentication vulnerability in Palo Alto Networks Expedition, a migration tool that can help convert firewall configuration from Checkpoint, Cisco, and other vendors to PAN-OS.

This security flaw, tracked as CVE-2024-5910, was patched in July, and threat actors can remotely exploit it to reset application admin credentials on Internet-exposed Expedition servers.

“Palo Alto Expedition contains a missing authentication vulnerability that allows an attacker with network access to takeover an Expedition admin account and potentially access configuration secrets, credentials, and other data,” CISA says.

While the cybersecurity agency has yet to provide more details on these attacks, Horizon3.ai vulnerability researcher Zach Hanley released a proof-of-concept exploit in October that can help chain this admin reset flaw with a CVE-2024-9464 command injection vulnerability (patched last month) to gain “unauthenticated” arbitrary command execution on vulnerable Expedition servers.

CVE-2024-9464 can be chained with other security flaws (also addressed by Palo Alto Networks in October) to take over firewall admin accounts and hijack PAN-OS firewalls.

Admins who can’t immediately install security updates to block incoming attacks are advised to restrict Expedition network access to authorized users, hosts, or networks.

“All Expedition usernames, passwords, and API keys should be rotated after upgrading to the fixed version of Expedition. All firewall usernames, passwords, and API keys processed by Expedition should be rotated after updating,” the company cautions.

Palo Alto Networks has yet to update its security advisory to warn customers of ongoing CVE-2024-5910 attacks.

CISA also added the vulnerability to its Known Exploited Vulnerabilities Catalog on Thursday. As required by the binding operational directive (BOD 22-01) issued in November 2021, U.S. federal agencies must now secure vulnerable Palo Alto Networks Expedition servers on their networks against attacks within three weeks, by November 28.

“These types of vulnerabilities are frequent attack vectors for malicious cyber actors and pose significant risks to the federal enterprise,” the cybersecurity agency warned.

Sergiu Gatlan

Kommentar verfassen

Deine E-Mail-Adresse wird nicht veröffentlicht. Erforderliche Felder sind mit * markiert

lade-bild
London, GB
7:00 am, Feb. 2, 2025
Wetter-Symbol 0°C
L: -1° | H: 1°
klarer Himmel
Luftfeuchtigkeit: 95 %
Druck: 1021 mb
Wind: 7 mph E
Windböe: 0 mph
UV-Index: 0
Niederschlag: 0 mm
Wolken: 10%
Regen Chance: 0%
Sichtbarkeit: 10 km
Sonnenaufgang: 7:37 am
Sonnenuntergang: 4:51 pm
TäglichStündlich
Tägliche VorhersageStündliche Vorhersage
Today 9:00 pm
Wetter-Symbol
-1° | 1°°C 0 mm 0% 7 mph 89 % 1025 mb 0 mm/h
Tomorrow 9:00 pm
Wetter-Symbol
3° | 9°°C 0 mm 0% 8 mph 91 % 1025 mb 0 mm/h
Di. Feb. 04 9:00 pm
Wetter-Symbol
6° | 9°°C 1 mm 100% 13 mph 93 % 1026 mb 0 mm/h
Mi. Feb. 05 9:00 pm
Wetter-Symbol
4° | 7°°C 0 mm 0% 10 mph 86 % 1045 mb 0 mm/h
Do. Feb. 06 9:00 pm
Wetter-Symbol
2° | 8°°C 0 mm 0% 8 mph 86 % 1045 mb 0 mm/h
Today 9:00 am
Wetter-Symbol
1° | 3°°C 0 mm 0% 5 mph 89 % 1022 mb 0 mm/h
Today 12:00 pm
Wetter-Symbol
5° | 7°°C 0 mm 0% 7 mph 73 % 1023 mb 0 mm/h
Today 3:00 pm
Wetter-Symbol
8° | 8°°C 0 mm 0% 7 mph 56 % 1022 mb 0 mm/h
Today 6:00 pm
Wetter-Symbol
5° | 5°°C 0 mm 0% 4 mph 74 % 1023 mb 0 mm/h
Today 9:00 pm
Wetter-Symbol
4° | 4°°C 0 mm 0% 4 mph 79 % 1025 mb 0 mm/h
Tomorrow 12:00 am
Wetter-Symbol
3° | 3°°C 0 mm 0% 4 mph 79 % 1025 mb 0 mm/h
Tomorrow 3:00 am
Wetter-Symbol
3° | 3°°C 0 mm 0% 4 mph 86 % 1025 mb 0 mm/h
Tomorrow 6:00 am
Wetter-Symbol
4° | 4°°C 0 mm 0% 4 mph 86 % 1025 mb 0 mm/h
Name Preis24H (%)
Bitcoin(BTC)
€96,790.55
-2.03%
Ethereum(ETH)
€3,011.76
-5.13%
XRP(XRP)
€2.81
-4.46%
Fesseln(USDT)
€0.96
0.00%
Solana(SOL)
€205.40
-7.96%
USDC(USDC)
€0.96
0.01%
Dogecoin(DOGE)
€0.293669
-7.08%
Shiba Inu(SHIB)
€0.000017
-7.78%
Pepe(PEPE)
€0.000012
-9.36%
Nach oben scrollen