ZeroHour
Help Net Securitypublished ()ingested @zeljkazorz

Attackers are chaining flaws to breach Palo Alto Networks firewalls

Vulnerabilities mentionedAll →

CVEVulnerabilityCVSSEPSSFlagsAffectedExposurePublished
CVE-2024-0012
+1 in the same advisory: …9474
Authentication Bypass in Palo Alto Networks PAN-OS Management Interface

CVE-2024-0012 is a critical authentication bypass (CWE-306) in the web management interface of Palo Alto Networks PAN-OS that lets an unauthenticated attacker with network access to that interface gain full PAN-OS administrator privileges. It is triggered simply by sending requests to an exposed management web interface, with no credentials or user interaction required. Once inside, the attacker can perform administrative actions, tamper with device configuration, and chain the bug with the related privilege escalation flaw CVE-2024-9474 for deeper compromise. Only PAN-OS 10.2, 11.0, 11.1 and 11.2 are affected; Cloud NGFW and Prisma Access are not, and risk is greatly reduced when the management interface is restricted to trusted internal IP addresses per vendor best practice. The flaw is being actively exploited: it was added to CISA KEV on 2024-11-18 with known ransomware use, and public reporting describes an ongoing campaign that has compromised more than 2,000 Palo Alto devices using this bug chained with CVE-2024-9474.

Do: Upgrade PAN-OS 10.2, 11.0, 11.1 and 11.2 deployments to the patched releases listed in the vendor advisory (security.paloaltonetworks.com/CVE-2024-0012), ensuring the chained privilege escalation bug CVE-2024-9474 is also addressed. Until patched, never expose the management web interface to untrusted networks or the internet, and restrict access to trusted internal IP addresses only. Review device logs and configurations for signs of compromise (unexpected admin activity or configuration changes) and hunt for persistence on any internet-exposed device.

9.3
group max
100% KEV ransomware PoC
  • Palo Alto Networks PAN-OS PAN-OS 10.2, 11.0, 11.1 and 11.2 (Cloud NGFW and Prisma Access are not impacted)
largetens of thousands of internet-exposed PAN-OS management interfaces, with 2,000+ devices already confirmed compromised
CVE-2025-0108
+1 in the same advisory: …0111
Authentication Bypass in Palo Alto Networks PAN-OS Management Interface

CVE-2025-0108 is a missing-authentication flaw (CWE-306) in the PAN-OS management web interface of Palo Alto Networks firewalls that lets an unauthenticated attacker with network access to that interface bypass login and invoke certain PHP scripts, reportedly via path-confusion tricks in the web server stack. Invoking the scripts does not yield remote code execution, but it can compromise the confidentiality and integrity of PAN-OS, such as by reading or modifying management-plane information. Any PAN-OS firewall whose management web interface is reachable by an attacker — for example, exposed to the internet or reachable from a compromised internal network — is affected, while Cloud NGFW and Prisma Access are not. The flaw is being actively exploited: CISA added it to the Known Exploited Vulnerabilities catalog on 2025-02-18, a public proof-of-concept is available, EPSS puts the 30-day exploitation probability at 98.5%, and headlines report attackers chaining this bug with other PAN-OS flaws to breach firewalls.

Do: Upgrade PAN-OS to a fixed release per the Palo Alto Networks advisory (security.paloaltonetworks.com/CVE-2025-0108), since the vendor has patched the flaw. Until patched, restrict management web interface access to trusted internal IP addresses or management-only network zones as recommended in the vendor's hardening guidance. Check management-interface logs for unauthenticated requests to PHP scripts and for signs of chaining with other recently exploited PAN-OS vulnerabilities.

8.8
group max
98% KEV PoC ×3
  • Palo Alto Networks PAN-OS
large≈ tens of thousands of internet-exposed PAN-OS management interfaces (subset of a much larger firewall install base)
Full article439 words · extracted from helpnetsecurity.com · click to collapse

Exploitation attempts targeting CVE-2025-0108, a recently disclosed authentication bypass vulnerability affecting the management web interface of Palo Alto Networks’ firewalls, are ramping up.

CVE-2025-0108 exploitation

“GreyNoise now sees 25 malicious IPs actively exploiting CVE-2025-0108, up from 2 on February 13,” the threat intelligence company shared on Tuesday. “This high-severity flaw allows unauthenticated attackers to execute specific PHP scripts, potentially leading to unauthorized access to vulnerable systems.”

CVE-2025-0108 + CVE-2024-9474 and/or CVE-2025-0111

Palo Alto Networks has updated the security advisory to confirm that it has observed exploit attempts chaining CVE-2025-0108 with:

  • CVE-2024-9474, an older OS command injection flaw that allows attackers to escalate their privileges and perform actions on the PAN firewall with root privileges, and
  • CVE-2025-0111, an authenticated file read vulnerability that allows attackers to read files on the PAN-OS filesystem that are readable by the “nobody” user.

CVE-2024-9474 has been actively exploited by attackers since November 2024.

The attackers leveraged CVE-2024-9474 and CVE-2024-0012, an auth bypass flaw, to exfiltrate sensitive files and information from vulnerable firewalls, deploy a command and control implant, an obfuscated PHP webshell, and the XMRig cryptocoin miner.

The existence of CVE-2025-0108 and CVE-2025-0111 was publicly disclosed by Palo Alto Networks via security advisories last week, following the release of PAN-OS versions that fixed these and other flaws.

Both security issues were flagged by external researchers. CVE-2025-0108 was reported by Assetnote researchers, who released technical details and a PoC exploit for it on the same day the advisory went out. Exploitation attempts started the next day.

What to do?

Organizations with internet-facing Palo Alto Networks’ firewalls that haven’t been upgraded immediately after the release of the latest security updates should assume the devices have been compromised. They should look for the presence of planted malware and for evidence of exploitation attempts coming from unexpected IPs. (Unfortunately, there are no publicly available indicators of compromise yet.)

According to GreyNoise, the top 3 source countries of attack traffic are the United States, Germany, and the Netherlands.

Both compromised and not compromised devices should be updated to one of the supported fixed versions. Organizations should also seriously consider securing access to their PAN devices’ management interface.

“Specifically, you should restrict management interface access to only trusted internal IP addresses,” Palo Alto Networks says.

“You can greatly reduce the risk of exploitation by restricting access to a jump box that is the only system allowed to access the management interface. This will ensure that attacks can succeed only if they obtain privileged access through those specified IP addresses.”

Subscribe to our breaking news e-mail alert to never miss out on the latest breaches, vulnerabilities and cybersecurity threats. Subscribe here!

Text extracted automatically; images, tables and formatting may be missing. Original: https://www.helpnetsecurity.com/2025/02/19/palo-alto-networks-firewalls-cve-2025-0108-cve-2024-9474-cve-2025-0111/