Palo Alto Networks patches two firewall zero-days used in attacks

Share:

Palo Alto Networks has finally released security updates for two actively exploited zero-day vulnerabilities in its Next-Generation Firewalls (NGFW).

The first flaw, tracked as CVE-2024-0012, is an authentication bypass found in the PAN-OS management web interface that remote attackers can exploit to gain administrator privileges without requiring authentication or user interaction.

The second one (CVE-2024-9474) is a PAN-OS privilege escalation security flaw that allows malicious PAN-OS administrators to perform actions on the firewall with root privileges.

While CVE-2024-9474 was disclosed today, the company first warned customers on November 8 to restrict access to their next-generation firewalls because of a potential RCE flaw tagged last Friday as CVE-2024-0012.

“Palo Alto Networks observed threat activity that exploits this vulnerability against a limited number of management web interfaces that are exposed to internet traffic coming from outside the network,” the company warned today regarding both zero-days.

“Palo Alto Networks has actively monitored and worked with customers to identify and further minimize the very small number of PAN-OS devices with management web interfaces exposed to the Internet or other untrusted networks, ” it added in a separate report providing indicators of compromise for ongoing attacks targeting the flaws.

While the company says these zero-days impact only a “very small number” of firewalls, threat monitoring platform Shadowserver reported on Friday that it’s tracking more than 8,700 exposed PAN-OS management interfaces.

Palo Alto PAN-OS exposed management interfaces
Palo Alto PAN-OS exposed management interfaces (Shadowserver)

Macnica threat researcher Yutaka Sejiyama also told BleepingComputer that he found over 11,000 IP addresses running Palo Alto PAN-OS management interfaces exposed online using Shodan. According to Shodan, the most vulnerable devices are in the United States, followed by India, Mexico, Thailand, and Indonesia.

The U.S. cybersecurity agency added the CVE-2024-0012 and CVE-2024-9474 vulnerabilities to its Known Exploited Vulnerabilities Catalog and ordered federal agencies to patch their systems within three weeks by December 9.

In early November, CISA also warned of ongoing attacks exploiting a critical missing authentication vulnerability (CVE-2024-5910) in the Palo Alto Networks Expedition firewall configuration migration tool, a flaw patched in July that threat actors can remotely exploit it to reset application admin credentials on Internet-exposed Expedition servers.

“These types of vulnerabilities are frequent attack vectors for malicious cyber actors and pose significant risks to the federal enterprise,” CISA warns.

Sergiu Gatlan

Leave a Comment

Your email address will not be published. Required fields are marked *

loader-image
London, GB
12:58 am, Feb 4, 2025
weather icon 7°C
L: 6° | H: 8°
broken clouds
Humidity: 93 %
Pressure: 1023 mb
Wind: 8 mph SW
Wind Gust: 0 mph
UV Index: 0
Precipitation: 0 mm
Clouds: 75%
Rain Chance: 0%
Visibility: 10 km
Sunrise: 7:34 am
Sunset: 4:54 pm
DailyHourly
Daily ForecastHourly Forecast
Today 9:00 pm
weather icon
6° | 8°°C 0.2 mm 20% 15 mph 95 % 1026 mb 0 mm/h
Tomorrow 9:00 pm
weather icon
4° | 8°°C 0 mm 0% 9 mph 86 % 1045 mb 0 mm/h
Thu Feb 06 9:00 pm
weather icon
2° | 8°°C 0 mm 0% 9 mph 86 % 1046 mb 0 mm/h
Fri Feb 07 9:00 pm
weather icon
2° | 6°°C 0 mm 0% 12 mph 92 % 1041 mb 0 mm/h
Sat Feb 08 9:00 pm
weather icon
1° | 4°°C 0.35 mm 35% 10 mph 89 % 1030 mb 0.15 mm/h
Today 3:00 am
weather icon
5° | 6°°C 0 mm 0% 6 mph 92 % 1024 mb 0 mm/h
Today 6:00 am
weather icon
6° | 6°°C 0 mm 0% 9 mph 95 % 1023 mb 0 mm/h
Today 9:00 am
weather icon
7° | 7°°C 0 mm 0% 11 mph 91 % 1022 mb 0 mm/h
Today 12:00 pm
weather icon
10° | 10°°C 0 mm 0% 13 mph 75 % 1022 mb 0 mm/h
Today 3:00 pm
weather icon
9° | 9°°C 0 mm 0% 15 mph 76 % 1021 mb 0 mm/h
Today 6:00 pm
weather icon
10° | 10°°C 0.2 mm 20% 12 mph 88 % 1022 mb 0 mm/h
Today 9:00 pm
weather icon
8° | 8°°C 0.2 mm 20% 10 mph 74 % 1026 mb 0 mm/h
Tomorrow 12:00 am
weather icon
6° | 6°°C 0 mm 0% 9 mph 82 % 1030 mb 0 mm/h
Name Price24H (%)
Bitcoin(BTC)
€97,906.69
4.75%
Ethereum(ETH)
€2,764.60
1.09%
XRP(XRP)
€2.65
15.82%
Tether(USDT)
€0.97
0.14%
Solana(SOL)
€209.46
9.76%
USDC(USDC)
€0.97
0.00%
Dogecoin(DOGE)
€0.275839
12.67%
Shiba Inu(SHIB)
€0.000016
12.87%
Pepe(PEPE)
€0.000011
9.31%
Scroll to Top