ZeroHour
Security Affairspublished ()ingested @securityaffairs

Palo Alto Networks confirmed active exploitation of recently disclosed zero

criticalExploit / PoC exploited in the wildimportance 60CVE-2024-9463CVE-2024-9465

Vulnerabilities mentionedAll →

CVEVulnerabilityCVSSEPSSFlagsAffectedExposurePublished
CVE-2024-9463
+1 in the same advisory: …9465
Unauthenticated OS Command Injection in Palo Alto Networks Expedition

CVE-2024-9463 is a critical (CVSS 4.0: 9.9) OS command injection flaw (CWE-78) in Palo Alto Networks Expedition, the vendor's on-premises migration and firewall-management tool. An unauthenticated, network-adjacent attacker can send crafted input to trigger arbitrary operating system command execution with root privileges, requiring no credentials or user interaction. A successful compromise exposes the sensitive data Expedition holds for managed PAN-OS firewalls, including usernames, cleartext passwords, device configurations, and device API keys, which can enable follow-on attacks against the firewalls themselves. Any organization running an Expedition deployment, typically as a management appliance that is sometimes reachable from the internet, is affected. Exploitation is confirmed in the wild: Palo Alto Networks confirmed active exploitation (reported alongside SQL injection flaw CVE-2024-9465), CISA added it to the Known Exploited Vulnerabilities catalog on 2024-11-14, and EPSS assigns a 98.5% probability of exploitation within 30 days.

Do: Upgrade Expedition to the vendor-fixed release per Palo Alto Networks' advisory, and remove or restrict internet exposure of the Expedition web interface; if patching is not immediately possible, CISA's required action is to apply vendor mitigations or discontinue use of the product. Because exploitation can disclose cleartext firewall usernames, passwords, and API keys, rotate those credentials and review firewall configurations and Expedition logs for signs of compromise, particularly given confirmed active exploitation alongside CVE-2024-9465.

9.9
group max
99% KEV
  • Palo Alto Networks Expedition
nichelikely in the low thousands of on-premises deployments worldwide, with public scans showing only on the order of hundreds of internet-exposed instances

Indicators of compromiseAll →

TypeIndicatorContext
sha2563c5f9034c86cb1952aa5bb07b4f77ce7d8bb5cc9fe5c029a32c72adc7e814668s pending assignment. “We observed a webshell with checksum 3C5F9034C86CB1952AA5BB07B4F77CE7D8BB5CC9FE5C029A32C72ADC7E814668.” reads the advisory. Restricting management interface acce
Full article538 words · extracted from securityaffairs.com · click to collapse

Pierluigi Paganini November 16, 2024

Palo Alto Networks confirmed active exploitation of a zero-day in its PAN-OS firewall and released new indicators of compromise (IoCs).

Last week, Palo Alto Networks warned customers to limit access to their next-gen firewall management interface due to a potential remote code execution vulnerability (CVSSv4.0 Base Score: 9.3) in PAN-OS. The cybersecurity company had no further details on the vulnerability and was not aware of the active exploitation of the flaw.

“Palo Alto Networks is aware of a claim of a remote code execution vulnerability via the PAN-OS management interface. At this time, we do not know the specifics of the claimed vulnerability. We are actively monitoring for signs of any exploitation.” reads the advisory. “We strongly recommend customers to ensure access to your management interface is configured correctly in accordance with our recommended best practice deployment guidelines. In particular, we recommend that you ensure that access to the management interface is possible only from trusted internal IPs and not from the Internet. The vast majority of firewalls already follow this Palo Alto Networks and industry best practice.”

Palo Alto Networks recommended reviewing best practices for securing management access to its devices.

Guidelines to secure the Palo Alto management interface include isolating it on a dedicated management VLAN, using jump servers for access, limiting inbound IP addresses to approved management devices, and allowing only secure communication (SSH, HTTPS) and PING for connectivity testing.

The cybersecurity firm stated that it does not have sufficient information about any indicators of compromise.

Now the company confirmed that the zero-day in its PAN-OS firewall management interface has been actively exploited in the wild and released indicators of compromise (IoCs).

“Palo Alto Networks has observed threat activity exploiting an unauthenticated remote command execution vulnerability against a limited number of firewall management interfaces which are exposed to the Internet. We are actively investigating this activity.” reads the advisory.

“We strongly recommend customers ensure access to your management interface is configured correctly in accordance with our recommended best practice deployment guidelines. In particular, we recommend that you immediately ensure that access to the management interface is possible only from trusted internal IPs and not from the Internet. The vast majority of firewalls already follow this Palo Alto Networks and industry best practice.”

The cybersecurity firm observed malicious activities originating from the following IP addresses

  • 136.144.17[.]*
  • 173.239.218[.]251
  • 216.73.162[.]*

The advisory pointed out that these IP addresses may be associated with VPN services, for this reason, they are also associated with legitimate user activity.

Palo Alto states that the zero-day has been exploited to deploy web shells on compromised devices, granting persistent remote access. A CVE is pending assignment.

“We observed a webshell with checksum 3C5F9034C86CB1952AA5BB07B4F77CE7D8BB5CC9FE5C029A32C72ADC7E814668.” reads the advisory.

Restricting management interface access to specific IPs significantly reduces exploitation risk, requiring privileged access first. In this scenario, the CVSS score drops to 7.5 (High).

This week, the U.S. Cybersecurity and Infrastructure Security Agency (CISA) added the following Palo Alto Expedition vulnerabilities to its Known Exploited Vulnerabilities (KEV) catalog:

  • CVE-2024-9463 Palo Alto Networks Expedition OS Command Injection Vulnerability
  • CVE-2024-9465 Palo Alto Networks Expedition SQL Injection Vulnerability

Follow me on Twitter: @securityaffairs and Facebook and Mastodon

Pierluigi Paganini

(SecurityAffairs – hacking, RCE)



Text extracted automatically; images, tables and formatting may be missing. Original: https://securityaffairs.com/171057/hacking/palo-alto-networks-zero-day-exploitation.html