Palo Alto Networks warns of firewall hijack bugs with public exploit

Teilen:

Palo Alto Networks warned customers today to patch security vulnerabilities (with public exploit code) that can be chained to let attackers hijack PAN-OS firewalls.

The flaws were found in Palo Alto Networks’ Expedition solution, which helps migrate configurations from other Checkpoint, Cisco, or supported vendors.

They can be exploited to access sensitive data, such as user credentials, that can help take over firewall admin accounts.

“Multiple vulnerabilities in Palo Alto Networks Expedition allow an attacker to read Expedition database contents and arbitrary files, as well as write arbitrary files to temporary storage locations on the Expedition system,” the company said in an advisory published on Wednesday.

“Combined, these include information such as usernames, cleartext passwords, device configurations, and device API keys of PAN-OS firewalls.”

These bugs are a combination of command injection, reflected cross-site scripting (XSS), cleartext storage of sensitive information, missing authentication, and SQL injection vulnerabilities:

  • CVE-2024-9463 (unauthenticated command injection vulnerability)
  • CVE-2024-9464 (authenticated command injection vulnerability)
  • CVE-2024-9465 (unauthenticated SQL injection vulnerability)
  • CVE-2024-9466 (cleartext credentials stored in logs)
  • CVE-2024-9467 (unauthenticated reflected XSS vulnerability)

Proof-of-concept exploit available

Horizon3.ai vulnerability researcher Zach Hanley, who found and reported four of the bugs, has also published a root cause analysis write-up that details how he found three of these flaws while researching the CVE-2024-5910 vulnerability (disclosed and patched in July), which allows attackers to reset Expedition application admin credentials.

Hanley also released a proof-of-concept exploit that chains the CVE-2024-5910 admin reset flaw with the CVE-2024-9464 command injection vulnerability to gain “unauthenticated” arbitrary command execution on vulnerable Expedition servers.

Palo Alto Networks says that, for the moment, there is no evidence that the security flaws have been exploited in attacks.

“The fixes for all listed issues are available in Expedition 1.2.96, and all later Expedition versions. The cleartext file affected by CVE-2024-9466 will be removed automatically during the upgrade,” Palo Alto Networks added today.

“All Expedition usernames, passwords, and API keys should be rotated after upgrading to the fixed version of Expedition. All firewall usernames, passwords, and API keys processed by Expedition should be rotated after updating.”

Admins who can’t immediately deploy today’s security updates must restrict Expedition network access to authorized users, hosts, or networks.

In April, the company started releasing hotfixes for a maximum-severity zero-day bug that had been actively exploited since March by a state-backed threat actor tracked as UTA0218 to backdoor PAN-OS firewalls.

Sergiu Gatlan

Kommentar verfassen

Deine E-Mail-Adresse wird nicht veröffentlicht. Erforderliche Felder sind mit * markiert

lade-bild
London, GB
7:05 pm, Juni 12, 2025
Wetter-Symbol 24°C
L: 23° | H: 25°
broken clouds
Luftfeuchtigkeit: 64 %
Druck: 1012 mb
Wind: 10 mph SW
Windböe: 0 mph
UV-Index: 0
Niederschlag: 0 mm
Wolken: 75%
Regen Chance: 0%
Sichtbarkeit: 10 km
Sonnenaufgang: 4:43 am
Sonnenuntergang: 9:17 pm
TäglichStündlich
Tägliche VorhersageStündliche Vorhersage
Today 10:00 pm
Wetter-Symbol
23° | 25°°C 0 mm 0% 4 mph 67 % 1013 mb 0 mm/h
Tomorrow 10:00 pm
Wetter-Symbol
16° | 27°°C 1 mm 100% 7 mph 94 % 1019 mb 0 mm/h
Sa. Juni 14 10:00 pm
Wetter-Symbol
17° | 23°°C 1 mm 100% 13 mph 96 % 1019 mb 0 mm/h
So. Juni 15 10:00 pm
Wetter-Symbol
13° | 22°°C 0.46 mm 46% 10 mph 84 % 1025 mb 0 mm/h
Mo. Juni 16 10:00 pm
Wetter-Symbol
14° | 25°°C 0 mm 0% 7 mph 86 % 1027 mb 0 mm/h
Today 10:00 pm
Wetter-Symbol
20° | 23°°C 0 mm 0% 4 mph 67 % 1013 mb 0 mm/h
Tomorrow 1:00 am
Wetter-Symbol
17° | 19°°C 0 mm 0% 3 mph 75 % 1015 mb 0 mm/h
Tomorrow 4:00 am
Wetter-Symbol
16° | 16°°C 0 mm 0% 3 mph 84 % 1017 mb 0 mm/h
Tomorrow 7:00 am
Wetter-Symbol
18° | 18°°C 0 mm 0% 7 mph 79 % 1018 mb 0 mm/h
Tomorrow 10:00 am
Wetter-Symbol
22° | 22°°C 0 mm 0% 7 mph 60 % 1019 mb 0 mm/h
Tomorrow 1:00 pm
Wetter-Symbol
26° | 26°°C 0 mm 0% 6 mph 41 % 1019 mb 0 mm/h
Tomorrow 4:00 pm
Wetter-Symbol
27° | 27°°C 0 mm 0% 7 mph 40 % 1019 mb 0 mm/h
Tomorrow 7:00 pm
Wetter-Symbol
25° | 25°°C 0 mm 0% 1 mph 51 % 1018 mb 0 mm/h
Name Preis24H (%)
Bitcoin(BTC)
€93,456.46
-0.57%
Ethereum(ETH)
€2,384.01
-2.34%
Fesseln(USDT)
€0.86
0.00%
XRP(XRP)
€1.94
-2.15%
Solana(SOL)
€138.06
-2.15%
USDC(USDC)
€0.86
0.00%
Dogecoin(DOGE)
€0.163569
-4.05%
Shiba Inu(SHIB)
€0.000011
-4.59%
Pepe(PEPE)
€0.000010
-4.62%
Peanut das Eichhörnchen(PNUT)
€0.236997
-5.02%
Nach oben scrollen