ZeroHour
The Recordpublished ()ingested

Experts warn of Palo Alto firewall exploitation after 2,000 compromises spotted

Vulnerabilities mentionedAll →

CVEVulnerabilityCVSSEPSSFlagsAffectedExposurePublished
CVE-2024-0012
+1 in the same advisory: …9474
Authentication Bypass in Palo Alto Networks PAN-OS Management Interface

CVE-2024-0012 is a critical authentication bypass (CWE-306) in the web management interface of Palo Alto Networks PAN-OS that lets an unauthenticated attacker with network access to that interface gain full PAN-OS administrator privileges. It is triggered simply by sending requests to an exposed management web interface, with no credentials or user interaction required. Once inside, the attacker can perform administrative actions, tamper with device configuration, and chain the bug with the related privilege escalation flaw CVE-2024-9474 for deeper compromise. Only PAN-OS 10.2, 11.0, 11.1 and 11.2 are affected; Cloud NGFW and Prisma Access are not, and risk is greatly reduced when the management interface is restricted to trusted internal IP addresses per vendor best practice. The flaw is being actively exploited: it was added to CISA KEV on 2024-11-18 with known ransomware use, and public reporting describes an ongoing campaign that has compromised more than 2,000 Palo Alto devices using this bug chained with CVE-2024-9474.

Do: Upgrade PAN-OS 10.2, 11.0, 11.1 and 11.2 deployments to the patched releases listed in the vendor advisory (security.paloaltonetworks.com/CVE-2024-0012), ensuring the chained privilege escalation bug CVE-2024-9474 is also addressed. Until patched, never expose the management web interface to untrusted networks or the internet, and restrict access to trusted internal IP addresses only. Review device logs and configurations for signs of compromise (unexpected admin activity or configuration changes) and hunt for persistence on any internet-exposed device.

9.3
group max
100% KEV ransomware PoC
  • Palo Alto Networks PAN-OS PAN-OS 10.2, 11.0, 11.1 and 11.2 (Cloud NGFW and Prisma Access are not impacted)
largetens of thousands of internet-exposed PAN-OS management interfaces, with 2,000+ devices already confirmed compromised
Full article384 words · extracted from therecord.media · click to collapse

Thousands of Palo Alto Networks firewalls have been compromised after two new vulnerabilities were disclosed earlier this month. 

Researchers at the U.K.-based Shadowserver Foundation said Thursday they found about 2,000 Palo Alto Networks firewalls breached worldwide, with hundreds in the U.S. and India affected. 

The hackers exploited CVE-2024-0012 and CVE-2024-9474 — two recently disclosed vulnerabilities. For nearly two weeks, experts have raised alarms about potential attacks after Palo Alto Networks released an advisory on the issues, which affect the company’s Next-Generation Firewalls (NGFW) management interfaces and can allow an intruder to take over systems.

Since then, Palo Alto’s own security team, Unit42, and researchers at Arctic Wolf have confirmed that hackers compromised systems using the two vulnerabilities. Palo Alto Networks has released fixes for both vulnerabilities earlier this week and urged customers to restrict access to the devices. The company said a functional exploit chaining CVE-2024-0012 and CVE-2024-9474 is publicly available.

Arctic Wolf said on Friday that in multiple intrusions it has observed, hackers sought to exfiltrate sensitive data from the firewall devices, including configuration files which include credentials allowing for deeper access to networks. 

Some attempts were made to steal operating system passwords and other files, according to Arctic Wolf. 

Palo Alto Networks said it is still investigating ongoing attacks that chain the two vulnerabilities together. In some instances, the hackers have dropped malware into affected systems. 

The Cybersecurity and Infrastructure Security Agency (CISA) ordered all federal civilian agencies to patch the vulnerabilities by December 9 and confirmed that it has seen evidence of both being exploited. 

Keeper Security’s Patrick Tiquet warned that the most immediate danger is attackers taking full control over affected firewalls, compromising the very systems designed to protect sensitive networks. 

“This opens the door for malware deployment, data theft, lateral movement within the network and even complete network shutdowns. For organizations relying on these firewalls, this could mean business disruption, loss of sensitive data and exposure to regulatory and financial consequences,” he explained. 

No previous article

No new articles

Jonathan Greig

is a Breaking News Reporter at Recorded Future News. Jonathan has worked across the globe as a journalist since 2014. Before moving back to New York City, he worked for news outlets in South Africa, Jordan and Cambodia. He previously covered cybersecurity at ZDNet and TechRepublic.

Text extracted automatically; images, tables and formatting may be missing. Original: https://therecord.media/palo-alto-networks-firewall-vulnerabilities-exploited-patched