ZeroHour
The Recordpublished ()ingested

Palo Alto updates advisory about firewall bug after discovering exploitation attempts

criticalAdvisory exploited in the wildimportance 60CVE-2024-0012

Vulnerabilities mentionedAll →

CVEVulnerabilityCVSSEPSSFlagsAffectedExposurePublished
CVE-2024-0012
Authentication Bypass in Palo Alto Networks PAN-OS Management Interface

CVE-2024-0012 is a critical authentication bypass (CWE-306) in the web management interface of Palo Alto Networks PAN-OS that lets an unauthenticated attacker with network access to that interface gain full PAN-OS administrator privileges. It is triggered simply by sending requests to an exposed management web interface, with no credentials or user interaction required. Once inside, the attacker can perform administrative actions, tamper with device configuration, and chain the bug with the related privilege escalation flaw CVE-2024-9474 for deeper compromise. Only PAN-OS 10.2, 11.0, 11.1 and 11.2 are affected; Cloud NGFW and Prisma Access are not, and risk is greatly reduced when the management interface is restricted to trusted internal IP addresses per vendor best practice. The flaw is being actively exploited: it was added to CISA KEV on 2024-11-18 with known ransomware use, and public reporting describes an ongoing campaign that has compromised more than 2,000 Palo Alto devices using this bug chained with CVE-2024-9474.

Do: Upgrade PAN-OS 10.2, 11.0, 11.1 and 11.2 deployments to the patched releases listed in the vendor advisory (security.paloaltonetworks.com/CVE-2024-0012), ensuring the chained privilege escalation bug CVE-2024-9474 is also addressed. Until patched, never expose the management web interface to untrusted networks or the internet, and restrict access to trusted internal IP addresses only. Review device logs and configurations for signs of compromise (unexpected admin activity or configuration changes) and hunt for persistence on any internet-exposed device.

9.3100% KEV ransomware PoC
  • Palo Alto Networks PAN-OS PAN-OS 10.2, 11.0, 11.1 and 11.2 (Cloud NGFW and Prisma Access are not impacted)
largetens of thousands of internet-exposed PAN-OS management interfaces, with 2,000+ devices already confirmed compromised
Full article613 words · extracted from therecord.media · click to collapse

Cybersecurity company Palo Alto Networks is warning customers that hackers are attempting to exploit a recently discovered vulnerability affecting a line of its firewall products. 

The company initially published an advisory about the issue on November 8 before updating it on Thursday to confirm that it is now being exploited. 

The bug, tagged as PAN-SA-2024-0015 and CVE-2024-0012, was upgraded to highest urgency and given a severity score of 9.3 out of 10. It affects the company’s Next-Generation Firewalls (NGFW) management interfaces and can allow an intruder to take over systems. Thousands of installations of the product are potentially affected, researchers say.

“Palo Alto Networks has observed threat activity exploiting an unauthenticated remote command execution vulnerability against a limited number of firewall management interfaces which are exposed to the Internet,” the company said, adding that it was still investigating the activity. 

 “We strongly recommend customers ensure access to your management interface is configured correctly in accordance with our recommended best practice deployment guidelines,” the advisory said. “In particular, we recommend that you immediately ensure that access to the management interface is possible only from trusted internal IPs and not from the Internet.”

Palo Alto Networks noted that the “vast majority of firewalls already follow” this advice. On Monday, U.K. cybersecurity nonprofit The Shadowserver Foundation said it found about 11,000 IP addresses exposed to the vulnerability — with hundreds located in several U.S. states. By Friday, the total number dipped to about 8,700. 

Other internet researchers pegged the number of exposed systems even higher at around 31,000.

Palo Alto Networks said the severity of the issue is significantly decreased if IP access is restricted because any potential attack “would first require privileged access to those IPs.”

The advisory provided detailed information on how customers can identify potentially exposed, internet-facing management interfaces that require remediation.

The company also noted that it can detect public-facing NGFW interfaces “through routine, nonintrusive Internet scanning” that has a “high degree of accuracy.”

“Based on detected IP addresses, Palo Alto Networks is able to attribute an Internet-exposed device back to a given customer by cross-referencing the IP to the serial number with our internal records,” the advisory said.

The company is notifying customers whether some of their devices were discovered, but it warned that the list “may not be complete, so please ensure that you verify that all of your devices are properly configured.”

The next steps will include releasing fixes for the bug and more threat prevention information, the advisory said. 

“We do not have sufficient information about any indicators of compromise to share at this time. If the management interface was exposed to the Internet, we advise the customer to monitor for suspicious threat activity such as unrecognized configuration changes or users,” the company explained.

The Cybersecurity and Infrastructure Security Agency published its own warning about the issue on Friday, noting that Palo Alto Networks recently became aware of “claims of an unverified remote code execution vulnerability.” An organization designed to provide security updates for companies in the water and wastewater sector also warned members about the issue. 

Several customers of Palo Alto Networks pointed to a now-deleted dark web post about a zero-day vulnerability being sold that targeted the devices in question. 

The advisory comes the same week as CISA warned of several other Palo Alto Networks vulnerabilities currently being exploited by hackers. 

No previous article

No new articles

Jonathan Greig

is a Breaking News Reporter at Recorded Future News. Jonathan has worked across the globe as a journalist since 2014. Before moving back to New York City, he worked for news outlets in South Africa, Jordan and Cambodia. He previously covered cybersecurity at ZDNet and TechRepublic.

Text extracted automatically; images, tables and formatting may be missing. Original: https://therecord.media/palo-alto-networks-firewall-vulnerability-exploited