ZeroHour
Infosecurity Magazinepublished ()ingested Kevin Poireault

Palo Alto Networks Confirms New Zero

criticalExploit / PoC exploited in the wildimportance 60CVE-2024-5910

Vulnerabilities mentionedAll →

CVEVulnerabilityCVSSEPSSFlagsAffectedExposurePublished
CVE-2024-5910
Unauthenticated Admin Account Takeover in Palo Alto Networks Expedition

CVE-2024-5910 is a missing authentication flaw (CWE-306) in Palo Alto Networks Expedition, a tool used to migrate, tune, and enrich firewall configurations. An attacker with network access to an Expedition instance can exploit the unauthenticated critical function to take over the Expedition admin account without any credentials. Once in control, the attacker can access configuration secrets, credentials, and other data imported into Expedition, and public research (horizon3.ai) shows it can be chained with other Expedition bugs for full system compromise. Any organization running Expedition — particularly instances reachable from the internet or shared networks — is affected. The flaw is actively exploited: it was added to CISA's Known Exploited Vulnerabilities catalog on 2024-11-07, carries a 91.8% EPSS exploitation probability, and is being exploited alongside related Expedition and firewall bugs (CVE-2024-9463, CVE-2024-9465).

Do: Apply the vendor's patched Expedition release per Palo Alto Networks' advisory; if the tool is no longer needed, decommission or discontinue it, as CISA permits. Until patched, restrict network access to Expedition to trusted management hosts and remove it from internet exposure. Check Expedition logs for signs of unauthorized admin access and rotate any credentials or secrets stored in the tool.

9.392% KEV PoC
  • Palo Alto Networks Expedition
nichelikely low thousands of deployments worldwide; unknown for internet-exposed instances
Full article309 words · extracted from infosecurity-magazine.com · click to collapse

An unauthenticated remote code execution (RCE) vulnerability against Palo Alto Networks’ internet-exposed firewall management interfaces is actively being exploited, according to the cybersecurity provider.

On November 8, Palo Alto published a security advisory to warn of a zero-day vulnerability affecting some of its PAN-OS firewall management interfaces.

The flaw is an unauthenticated RCE vulnerability affecting internet-exposed new-generation firewall (NGFW) internet management interfaces.

CVSS Score of 9.3

Although the vulnerability has not yet been allocated a CVE, Palo Alto assessed it as critical, with a CVSS of 9.3.

However, the vulnerability only affects public-facing NGFW management interfaces. The manufacturer believes neither Prisma Access nor Cloud NGFW are affected.

“If the management interface access is restricted to IPs, the risk of exploitation is greatly limited, as any potential attack would first require privileged access to those IPs. CVSS for this scenario is 7.5 High,” added the company.

While Palo Alto did not initially mention any threat activity related to this new vulnerability, the firm updated its advisory on November 14 to confirm it has now observed in-the-wild exploitation.

Read more about Palo Alto zero-days: Palo Alto Networks Warns About Critical Zero-Day in PAN-OS

Palo Alto Working on a Patch

Palo Alto informed customers that it is actively developing patches and threat prevention signatures, which are expected to be released soon.

“We strongly recommend customers to ensure access to your management interface is configured correctly in accordance with our recommended best practice deployment guidelines,” Palo Alto added in its advisory.

This comes only days after the US Cybersecurity and Infrastructure Security Agency (CISA) added another vulnerability affecting a Palo Alto product – this time Palo Alto Expedition (CVE-2024-5910) – to its Known Exploited Vulnerability (KEV) catalog.

Fortinet, another firewall provider, has also experienced the disclosure of several zero-day vulnerabilities being actively exploited in the past month.

Photo credit: Michael Vi/Tada Images/Shutterstock

Text extracted automatically; images, tables and formatting may be missing. Original: https://www.infosecurity-magazine.com/news/palo-alto-confirms-new-0day/