Palo Alto Networks Patches Critical Firewall Vulnerability
Vulnerabilities mentionedAll →
| CVE | Vulnerability | CVSS | EPSS | Flags | Affected | Exposure | Published |
|---|---|---|---|---|---|---|---|
| CVE-2024-9474 | Root Privilege Escalation via Command Injection in Palo Alto Networks PAN-OS CVE-2024-9474 is an OS command injection flaw (CWE-78) in the Palo Alto Networks PAN-OS management web interface that allows a PAN-OS administrator to perform actions on the firewall with root privileges. It is triggered by an authenticated administrator through the management interface, and it becomes far more serious when chained with the separately disclosed CVE-2024-0012 management-interface authentication bypass, which hands unauthenticated attackers initial access before they escalate to root. A successful attacker gains root-level control of the device, enough to alter configurations, harvest credentials, and pivot into connected networks. Only PAN-OS deployments are affected — Palo Alto Networks states Cloud NGFW and Prisma Access are not impacted. Exploitation is confirmed in the wild: the flaw was added to CISA's KEV on 2024-11-18 with known ransomware use, reporting describes over 2,000 PAN-OS devices compromised in an ongoing campaign, and public PoC/exploit code is available. Do: Upgrade affected PAN-OS systems to the patched releases identified in the Palo Alto Networks security advisory, and also remediate CVE-2024-0012, which attackers are chaining with this flaw. Until patched, ensure the management interface is not exposed to untrusted networks including the internet, per CISA's required action. Because successful attackers obtain root access, review management and configuration audit logs for unexpected activity and rotate management credentials on any device showing signs of compromise. | 6.9 | 95% | KEV ransomware PoC ×2 |
| large≈tens of thousands of internet-exposed PAN-OS management interfaces, with 2,000+ devices confirmed compromised |
Full article322 words · extracted from infosecurity-magazine.com · click to collapse
Palo Alto Networks has released a security patch to fix a critical vulnerability in instances of its firewall management interfaces.
The security vendor disclosed the flaw on November 8 and later confirmed evidence of in-the-wild exploitation. It was initially tracked by Palo Alto as PAN-SA-2024-0015.
It has now been allocated a common vulnerabilities and exposures (CVE) number, CVE-2024-12.
Critical, Actively Exploited Vulnerability
The vulnerability is an authentication bypass found in the PAN-OS management web interface used to manage Palo Alto’s next-generation firewalls (NGFWs).
It affects PAN-OS 10.2, PAN-OS 11.0, PAN-OS 11.1 and PAN-OS 11.2 software. Cloud NGFW and Prisma Access are not impacted.
Exploiting this flaw could enable an unauthenticated attacker network access to the management web interface. With this access they could gain PAN-OS administrator privileges to perform administrative actions and tamper with the configuration.
Palo Alto gave the flaw a common vulnerability severity score (CVSS) of 9.3, meaning it is critical.
The vendor also said on November 14 that it “observed threat activity that exploits this vulnerability against a limited number of management web interfaces that are exposed to internet traffic coming from outside the network.”
Palo Alto Networks: Patch Urgently
A patch was released on November 18 for the following versions: PAN-OS 10.2.12-h2, PAN-OS 11.0.6-h1, PAN-OS 11.1.5-h1, PAN-OS 11.2.4-h1 and all later PAN-OS versions.
This patch also fixes CVE-2024-9474, another vulnerability in PAN-OS disclosed on November 18.
The vendor said that Palo Alto NGFW users with these versions should urgently patch it.
“In addition, in an attempt to provide the most seamless upgrade path for our customers, we are making fixes available for other TAC-preferred and commonly deployed maintenance releases,” said the Palo Alto advisory.
The vendor also said that the risk of this issue can be reduced by restricting access to the management web interface to only trusted internal IP addresses.
Read now: A Guide to Zero-Day Vulnerabilities and Exploits for the Uninitiated
Photo credit: Mojahid Mottakin/viewimage/Shutterstock
Text extracted automatically; images, tables and formatting may be missing. Original: https://www.infosecurity-magazine.com/news/palo-alto-patches-critical/