Palo Alto Networks Zero
Vulnerabilities mentionedAll →
| CVE | Vulnerability | CVSS | EPSS | Flags | Affected | Exposure | Published |
|---|---|---|---|---|---|---|---|
| CVE-2024-3400 | Unauthenticated Root Command Injection in Palo Alto Networks PAN-OS GlobalProtect Palo Alto Networks PAN-OS contains a command injection flaw (CWE-77, with improper input validation per CWE-20) in its GlobalProtect feature, allowing an unauthenticated attacker to execute arbitrary operating-system commands with root privileges on the affected firewall. The flaw is triggered through the GlobalProtect interface, which in most deployments is reachable from untrusted networks, so no valid user credentials or prior access are required. Successful exploitation yields full root control of the firewall, the most powerful position in a network perimeter, enabling traffic interception, configuration tampering, and use as a foothold for further compromise. All PAN-OS firewalls running affected releases with the GlobalProtect feature are exposed; CISA added the issue to the KEV catalog on 2024-04-12 with ransomware use noted, and EPSS puts the 30-day exploitation probability at 100% (100th percentile). No public proof-of-concept is recorded in the source data, but confirmed in-the-wild exploitation makes patching urgent. Do: Apply the PAN-OS patches released in Palo Alto Networks' bulletin according to its published patch schedule, prioritizing internet-facing firewalls. Until patched, enable the vendor's Threat Prevention signatures as required by CISA KEV, restrict exposure of the GlobalProtect interface to trusted sources where possible, and review logs and device configuration for signs of compromise given confirmed exploitation with known ransomware use. | 10.0 | 100% | KEV ransomware PoC ×2 |
| large≈10,000–100,000 internet-exposed PAN-OS firewalls with GlobalProtect enabled |
Full article314 words · extracted from infosecurity-magazine.com · click to collapse
Palo Alto Networks has detected targeted assaults exploiting a recently unearthed critical zero-day vulnerability within its PAN-OS software, designated CVE-2024-3400 with a CVSS score of 10.0.
This flaw enables unauthorized actors to execute arbitrary code with root privileges on affected firewalls. Identified as Operation MidnightEclipse, these targeted attacks have been closely monitored following the discovery of the vulnerability.
The vulnerability affects firewalls running PAN-OS 10.2, 11.0 and 11.1 and configured with specific features enabled.
In an advisory published last Friday, Palo Alto Networks confirmed targeted attacks leveraging this flaw, attributing known exploitation to a single threat actor while acknowledging the potential for future exploitation by additional actors.
Operation MidnightEclipse encompasses post-exploitation activities, including the deployment of a Python-based backdoor named UPSTYLE via a cronjob executing commands remotely every minute.
In their advisory, Palo Alto Networks has shared detailed insights into the backdoor’s behavior, including its persistence mechanisms, command execution and cleanup processes.
“Anytime a vulnerability impacts devices directly connected to the Internet, it’s a cause for concern. The fact that these are being actively exploited makes this additionally troublesome,” warned Erich Kron, security awareness advocate at KnowBe4.
“Organizations with vulnerable versions of the operating system should take immediate actions to mitigate the threat by disabling features related to the vulnerability [...] while keeping a vigilant watch for potential malicious network traffic or code execution on the devices.”
To address the issue, Palo Alto Networks advised users to apply hotfixes released on Sunday for affected PAN-OS versions and enable specific threat prevention measures. The company is also offering its Unit 42 Managed Threat Hunting XQL queries to help identify signs of exploitation within network logs.
Gratitude is extended to Volexity for discovering the vulnerability, highlighting the significance of collaboration in combating cybersecurity threats.
Read more on this vulnerability: Palo Alto Networks Warns About Critical Zero-Day in PAN-OS
Image credit: Tada Images / Shutterstock.com
Text extracted automatically; images, tables and formatting may be missing. Original: https://www.infosecurity-magazine.com/news/palo-alto-networks-zero-day-flaw/