More than 2,000 Palo Alto Networks firewalls hacked exploiting recently patched zero
Vulnerabilities mentionedAll →
| CVE | Vulnerability | CVSS | EPSS | Flags | Affected | Exposure | Published |
|---|---|---|---|---|---|---|---|
| CVE-2024-0012 +1 in the same advisory: …9474 | Authentication Bypass in Palo Alto Networks PAN-OS Management Interface CVE-2024-0012 is a critical authentication bypass (CWE-306) in the web management interface of Palo Alto Networks PAN-OS that lets an unauthenticated attacker with network access to that interface gain full PAN-OS administrator privileges. It is triggered simply by sending requests to an exposed management web interface, with no credentials or user interaction required. Once inside, the attacker can perform administrative actions, tamper with device configuration, and chain the bug with the related privilege escalation flaw CVE-2024-9474 for deeper compromise. Only PAN-OS 10.2, 11.0, 11.1 and 11.2 are affected; Cloud NGFW and Prisma Access are not, and risk is greatly reduced when the management interface is restricted to trusted internal IP addresses per vendor best practice. The flaw is being actively exploited: it was added to CISA KEV on 2024-11-18 with known ransomware use, and public reporting describes an ongoing campaign that has compromised more than 2,000 Palo Alto devices using this bug chained with CVE-2024-9474. Do: Upgrade PAN-OS 10.2, 11.0, 11.1 and 11.2 deployments to the patched releases listed in the vendor advisory (security.paloaltonetworks.com/CVE-2024-0012), ensuring the chained privilege escalation bug CVE-2024-9474 is also addressed. Until patched, never expose the management web interface to untrusted networks or the internet, and restrict access to trusted internal IP addresses only. Review device logs and configurations for signs of compromise (unexpected admin activity or configuration changes) and hunt for persistence on any internet-exposed device. | 9.3 group max | 100% | KEV ransomware PoC |
| largetens of thousands of internet-exposed PAN-OS management interfaces, with 2,000+ devices already confirmed compromised |
Full article442 words · extracted from securityaffairs.com · click to collapse
Pierluigi Paganini
November 22, 2024

Threat actors already hacked thousands of Palo Alto Networks firewalls exploiting recently patched zero-day vulnerabilities.
Thousands of Palo Alto Networks firewalls have reportedly been compromised in attacks exploiting recently patched zero-day vulnerabilities (CVE-2024-0012 and CVE-2024-9474) in PAN-OS.
CVE-2024-0012 is a vulnerability in Palo Alto Networks PAN-OS that allows unauthenticated attackers with network access to the management web interface to bypass authentication and gain administrator privileges. This access enables administrative actions, configuration tampering, or exploitation of other vulnerabilities like CVE-2024-9474. The issue affects PAN-OS versions 10.2, 11.0, 11.1, and 11.2 but does not impact Cloud NGFW or Prisma Access.
CVE-2024-9474 is a privilege escalation vulnerability in Palo Alto Networks PAN-OS software allows a PAN-OS administrator with access to the management web interface to perform actions on the firewall with root privileges.
This week, the U.S. Cybersecurity and Infrastructure Security Agency (CISA) added both vulnerabilities to its Known Exploited Vulnerabilities (KEV) catalog.
In mid-November, Palo Alto Networks confirmed it had observed threat activity exploiting an unauthenticated remote command execution vulnerability against a limited number of firewall management interfaces which are exposed to the Internet.
Palo Alto said the zero-day has been exploited to deploy web shells on compromised devices, granting persistent remote access.
“Palo Alto Networks and Unit 42 are engaged in tracking a limited set of exploitation activity related to CVE-2024-0012 and CVE-2024-9474 and are working with external researchers, partners, and customers to share information transparently and rapidly.” reads the report published by Palo Alto.
The cybersecurity firm initially observed malicious activities originating from the following IP addresses
- 136.144.17[.]*
- 173.239.218[.]251
- 216.73.162[.]*
The advisory pointed out that these IP addresses may be associated with VPN services, for this reason, they are also associated with legitimate user activity.
“Palo Alto Networks continues to track additional threat activity following the public release of technical insights and artifacts by third-party researchers beginning on Nov. 19, 2024. At this time, Unit 42 assesses with moderate to high confidence that a functional exploit chaining CVE-2024-0012 and CVE-2024-9474 is publicly available, which will enable broader threat activity.” continues the report. “Unit 42 has also observed both manual and automated scanning activity aligning with the timeline of third-party artifacts becoming widely available.”
The investigation is ongoing, and the cybersecurity firm updated the list of Indicators of Compromise.
Shadowserver researchers, who are tracking the number of compromised Palo Alto Networks firewalls, reported that approximately 2,000 have been hacked due to a CVE-2024-0012/CVE-2024-9474 campaign. Most of the hacked devices are in the US (554) and India (461).
Follow me on Twitter: @securityaffairs and Facebook and Mastodon
(SecurityAffairs – hacking, PAN-OS)
Text extracted automatically; images, tables and formatting may be missing. Original: https://securityaffairs.com/171268/hacking/palo-alto-networks-firewalls-hacked-zero-days.html