ZeroHour
Infosecurity Magazinepublished ()ingested Kevin Poireault

Hackers Chain Exploits of Three Palo Alto Networks Firewall Flaws

highRansomware exploited in the wildimportance 60CVE-2025-0108CVE-2025-0111CVE-2024-9474

Vulnerabilities mentionedAll →

CVEVulnerabilityCVSSEPSSFlagsAffectedExposurePublished
CVE-2024-9474
Root Privilege Escalation via Command Injection in Palo Alto Networks PAN-OS

CVE-2024-9474 is an OS command injection flaw (CWE-78) in the Palo Alto Networks PAN-OS management web interface that allows a PAN-OS administrator to perform actions on the firewall with root privileges. It is triggered by an authenticated administrator through the management interface, and it becomes far more serious when chained with the separately disclosed CVE-2024-0012 management-interface authentication bypass, which hands unauthenticated attackers initial access before they escalate to root. A successful attacker gains root-level control of the device, enough to alter configurations, harvest credentials, and pivot into connected networks. Only PAN-OS deployments are affected — Palo Alto Networks states Cloud NGFW and Prisma Access are not impacted. Exploitation is confirmed in the wild: the flaw was added to CISA's KEV on 2024-11-18 with known ransomware use, reporting describes over 2,000 PAN-OS devices compromised in an ongoing campaign, and public PoC/exploit code is available.

Do: Upgrade affected PAN-OS systems to the patched releases identified in the Palo Alto Networks security advisory, and also remediate CVE-2024-0012, which attackers are chaining with this flaw. Until patched, ensure the management interface is not exposed to untrusted networks including the internet, per CISA's required action. Because successful attackers obtain root access, review management and configuration audit logs for unexpected activity and rotate management credentials on any device showing signs of compromise.

6.995% KEV ransomware PoC ×2
  • Palo Alto Networks PAN-OS
large≈tens of thousands of internet-exposed PAN-OS management interfaces, with 2,000+ devices confirmed compromised
CVE-2025-0108
+1 in the same advisory: …0111
Authentication Bypass in Palo Alto Networks PAN-OS Management Interface

CVE-2025-0108 is a missing-authentication flaw (CWE-306) in the PAN-OS management web interface of Palo Alto Networks firewalls that lets an unauthenticated attacker with network access to that interface bypass login and invoke certain PHP scripts, reportedly via path-confusion tricks in the web server stack. Invoking the scripts does not yield remote code execution, but it can compromise the confidentiality and integrity of PAN-OS, such as by reading or modifying management-plane information. Any PAN-OS firewall whose management web interface is reachable by an attacker — for example, exposed to the internet or reachable from a compromised internal network — is affected, while Cloud NGFW and Prisma Access are not. The flaw is being actively exploited: CISA added it to the Known Exploited Vulnerabilities catalog on 2025-02-18, a public proof-of-concept is available, EPSS puts the 30-day exploitation probability at 98.5%, and headlines report attackers chaining this bug with other PAN-OS flaws to breach firewalls.

Do: Upgrade PAN-OS to a fixed release per the Palo Alto Networks advisory (security.paloaltonetworks.com/CVE-2025-0108), since the vendor has patched the flaw. Until patched, restrict management web interface access to trusted internal IP addresses or management-only network zones as recommended in the vendor's hardening guidance. Check management-interface logs for unauthenticated requests to PHP scripts and for signs of chaining with other recently exploited PAN-OS vulnerabilities.

8.8
group max
98% KEV PoC ×3
  • Palo Alto Networks PAN-OS
large≈ tens of thousands of internet-exposed PAN-OS management interfaces (subset of a much larger firewall install base)
Full article345 words · extracted from infosecurity-magazine.com · click to collapse

Hackers are actively trying to simultaneously exploit three vulnerabilities in unpatched Palo Alto Networks firewall appliances.

These flaws, all affecting Palo Alto’s PAN-OS web management interface, include CVE-2025-0108, an authentication bypass, CVE-2025-0111, an authenticated file read vulnerability, and CVE-2024-9474, a privilege escalation vulnerability.

The first two are high-severity vulnerabilities, with CVSS scores of 8.8 and 7.1, respectively. Palo Alto disclosed the vulnerabilities and published patches for both flaws on February 12, 2025.

The third is a slightly less severe with a CVSS score of 6.9 and is an older flaw, with a fix released in November 2024.

First detected by cyber threat intelligence organizations, the chain exploit was acknowledged by Palo Alto on February 19.

Increasing PAN-OS Firewall Flaws Exploits

Researchers at Assetnote, who first detected CVE-2025-0108 , published a proof-of-concept exploit on February 12 showing how the flaw could be chained together with CVE-2024-9474 to gain root privileges on unpatched PAN-OS firewalls.

In the following days, several organizations, including network threat intelligence firm GreyNoise and the non-profit Shadowserver Foundation, reported that threat actors had begun actively exploiting the flaw, with attempts coming from two IP addresses.

The US Cybersecurity and Infrastructure Security Agency (CISA) added CVE-2025-0108 to its Known Exploited Vulnerabilities (KEV) catalog on February 18.

The next day, Palo Alto updated its advisories for CVE-2025-0108 and CVE-2025-0111. It added that it “has observed exploit attempts chaining CVE-2025-0108 with CVE-2024-9474 and CVE-2025-0111 on unpatched and unsecured PAN-OS web management interfaces.”

The software provider did not provide details on the exploit chain but said the complexity of the attack was “low.” 

GreyNoise has observed an increase in IP addresses targeting CVE-2025-0108, rising from two on February 13 to 25 five days later.

The primary sources of these attacks are in the US, Germany and the Netherlands, but this doesn’t necessarily reflect the attackers’ actual locations.

“Organizations relying on PAN-OS firewalls should assume that unpatched devices are being targeted and take immediate steps to secure them,” the GreyNoise researchers warned.

Photo credits: viewimage/Tada Images/Shutterstock

Read now: China-Linked Espionage Tools Used in Recent Ransomware Attack

Text extracted automatically; images, tables and formatting may be missing. Original: https://www.infosecurity-magazine.com/news/hackers-chain-exploits-three-palo/