ZeroHour
Help Net Securitypublished ()ingested @zeljkazorz

Attackers are exploiting 2 zero-days in Palo Alto Networks firewalls (CVE-2024-0012, CVE-2024-9474)

Vulnerabilities mentionedAll →

CVEVulnerabilityCVSSEPSSFlagsAffectedExposurePublished
CVE-2024-0012
+1 in the same advisory: …9474
Authentication Bypass in Palo Alto Networks PAN-OS Management Interface

CVE-2024-0012 is a critical authentication bypass (CWE-306) in the web management interface of Palo Alto Networks PAN-OS that lets an unauthenticated attacker with network access to that interface gain full PAN-OS administrator privileges. It is triggered simply by sending requests to an exposed management web interface, with no credentials or user interaction required. Once inside, the attacker can perform administrative actions, tamper with device configuration, and chain the bug with the related privilege escalation flaw CVE-2024-9474 for deeper compromise. Only PAN-OS 10.2, 11.0, 11.1 and 11.2 are affected; Cloud NGFW and Prisma Access are not, and risk is greatly reduced when the management interface is restricted to trusted internal IP addresses per vendor best practice. The flaw is being actively exploited: it was added to CISA KEV on 2024-11-18 with known ransomware use, and public reporting describes an ongoing campaign that has compromised more than 2,000 Palo Alto devices using this bug chained with CVE-2024-9474.

Do: Upgrade PAN-OS 10.2, 11.0, 11.1 and 11.2 deployments to the patched releases listed in the vendor advisory (security.paloaltonetworks.com/CVE-2024-0012), ensuring the chained privilege escalation bug CVE-2024-9474 is also addressed. Until patched, never expose the management web interface to untrusted networks or the internet, and restrict access to trusted internal IP addresses only. Review device logs and configurations for signs of compromise (unexpected admin activity or configuration changes) and hunt for persistence on any internet-exposed device.

9.3
group max
100% KEV ransomware PoC
  • Palo Alto Networks PAN-OS PAN-OS 10.2, 11.0, 11.1 and 11.2 (Cloud NGFW and Prisma Access are not impacted)
largetens of thousands of internet-exposed PAN-OS management interfaces, with 2,000+ devices already confirmed compromised
Full article553 words · extracted from helpnetsecurity.com · click to collapse

Palo Alto Networks has released fixes for two vulnerabilities (CVE-2024-0012 and CVE-2024-9474) in its next-generation firewalls that have been exploited by attackers as zero-days.

CVE-2024-0012 CVE-2024-9474

About the vulnerabilities (CVE-2024-0012, CVE-2024-9474)

CVE-2024-0012 stems from missing authentication for a critical function and allows unauthenticated attackers with network access to the management web interface “to gain PAN-OS administrator privileges to perform administrative actions, tamper with the configuration, or exploit other authenticated privilege escalation vulnerabilities like CVE-2024-9474,” according to Palo Alto Networks.

CVE-2024-0012 is the (previously unspecified) unauthenticated remote command execution zero-day that the company started warning about ten days ago, after urging customers to appropriately configure and secure access to firewall management interfaces exposed to the internet.

CVE-2024-9474 is an OS command injection flaw that allows a PAN-OS administrator with access to the management web interface to escalate their privileges and perform actions on the firewall with root privileges.

The company’s product security researchers pinpointed the vulnerabilities based on observed threat activity.

Cloud NGFW and Prisma Access are not impacted by these flaws.

Exploitation detection and remediation

The company’s incident responders are tracking the initial exploitation of CVE-2024-0012 under the name Operation Lunar Peek.

“Palo Alto Networks has identified threat activity targeting a limited number of device management web interfaces. This activity has primarily originated from IP addresses known to proxy/tunnel traffic for anonymous VPN services,” they explained in a separate threat brief, which also provides indicators of compromise.

“Observed post-exploitation activity includes interactive command execution and dropping malware, such as webshells, on the firewall.”

Limiting access to the management interface only to trusted internal IP addresses or a specified jump box reduces the risk of exploitation, but upgrading to a fixed version of the OS should be prioritized.

Both vulnerabilities have been fixed in PAN-OS 10.2.12-h2, PAN-OS 11.0.6-h1, PAN-OS 11.1.5-h1, PAN-OS 11.2.4-h1, and all later PAN-OS versions. CVE-2024-9474 has additionally been addressed in PAN-OS 10.1.14-h6.

“If your management web interface was exposed to the internet, then we advise you to closely monitor your network for suspicious threat activity, such as unrecognized configuration changes or suspicious users. We are scanning Telemetry data and customer uploaded tech support files (TSF) for evidence of threat activity and updating the case notes accordingly,” Palo Alto says.

Customers who find evidence of compromise are advised to take the affected devices offline and contact the company’s Global Customer Support to schedule a forced Enhanced Factory Reset (EFR). Further action will be required by the customers to finalize the clean-up.

UPDATE (November 19, 2024, 03:25 a.m. ET):

Censys has identified 13,324 publicly exposed – but not necessarily vulnerable – NGFW management interfaces.

“A large proportion of these (34%) are geolocated in the United States. Censys observed about 8% of the exposed instances to be associated with Amazon (ASN 16509),” the company said.

UPDATE (November 19, 2024, 07:40 a.m. ET):

WatchTowr researchers have published an analysis of how the two bugs can be concatenated to achieve unauthenticated remote code execution.

They’ve refrained from publishing a PoC exploit, but they have released a Nuclei template that admins can use to check if their hosts are affected.

UPDATE (November 21, 2024, 07:25 a.m. ET):

Shadowserver Foundation has detected around 2,000 compromised devices.

Subscribe to our breaking news e-mail alert to never miss out on the latest breaches, vulnerabilities and cybersecurity threats. Subscribe here!

Text extracted automatically; images, tables and formatting may be missing. Original: https://www.helpnetsecurity.com/2024/11/18/cve-2024-0012-cve-2024-9474/