ZeroHour
CyberScooppublished ()ingested @jeffstone500

US Cyber Command highlights Palo Alto Networks security patch, citing foreign espionage

criticalVulnerability exploited in the wildimportance 60CVE-2020-2021

Vulnerabilities mentionedAll →

CVEVulnerabilityCVSSEPSSFlagsAffectedExposurePublished
CVE-2020-2021
SAML Authentication Bypass in Palo Alto Networks PAN-OS

CVE-2020-2021 is an improper signature-verification flaw (CWE-347) in PAN-OS SAML authentication that lets an unauthenticated network-based attacker bypass identity verification when SAML is enabled and the 'Validate Identity Provider Certificate' option is left unchecked. An attacker with network access to a vulnerable GlobalProtect gateway or portal, GlobalProtect Clientless VPN, Captive Portal, or Prisma Access can gain access to protected resources permitted by the configured authentication and security policies, without affecting session integrity or availability for regular users. If SAML is used to protect the PAN-OS or Panorama web interfaces, the attacker can log in as an administrator and perform administrative actions, making this a worst-case CVSS 10.0 (critical) issue. Affected deployments run PAN-OS 9.1 before 9.1.3, 9.0 before 9.0.9, 8.1 before 8.1.15, or any 8.0 release (end-of-life); PAN-OS 7.1 is not affected, and the flaw cannot be exploited where SAML is unused or certificate validation is enabled. The vendor reported no malicious exploitation at disclosure, but the flaw has since been added to CISA's Known Exploited Vulnerabilities catalog (March 2022) with known ransomware use, and headlines tie it to foreign espionage and APT activity chaining VPN flaws.

Do: Upgrade to PAN-OS 9.1.3, 9.0.9, or 8.1.15 or later as applicable, and migrate off EOL PAN-OS 8.0; PAN-OS 7.1 requires no action. As an immediate mitigation, enable (check) the 'Validate Identity Provider Certificate' option in the SAML Identity Provider Server Profile. Restrict the PAN-OS and Panorama web interfaces to a trusted management network and audit whether SAML is used for GlobalProtect, Captive Portal, Prisma Access, or administrator authentication to confirm exposure.

10.04% KEV ransomware
  • Palo Alto Networks PAN-OS 9.1 versions earlier than 9.1.3; 9.0 versions earlier than 9.0.9; 8.1 versions earlier than 8.1.15; all PAN-OS 8.0 versions (EOL); PAN-OS 7.1 not affected
largetens of thousands of internet-exposed PAN-OS firewalls, gateways and management interfaces, of an installed base of hundreds of thousands
Full article535 words · extracted from cyberscoop.com · click to collapse
Skip to main content

Get our latest cybersecurity news first on Google.

Click here!

The issue ranks as a 10.0 on the severity scale.

dod apache struts
(chucka_nc / flickr )

U.S. cyber officials are urging American companies and individuals who rely on a popular security product to update their systems immediately, before foreign hackers can exploit a flaw in the technology to steal protected information.

The Department of Homeland Security and U.S. Cyber Command said Monday that a “critical” flaw in technology from Palo Alto Networks, a multinational security firm based in California, could enable attackers “with network access” to obtain sensitive information. The flaw exists in PAN-OS, the operating system on firewalls and corporate virtual private network application products.

Cyber Command said in a tweet that advanced hacking groups “will likely attempt exploit soon.”

Palo Alto Networks issued a patch on Monday for the security flaw, the start of a weeks or months-long process in which corporate security teams will start updating their technologies to fend off hacking groups.

The software flaw, officially dubbed CVE-2020-2021, was designated a 10.0 on the severity scale in the U.S. National Institute of Science and Technology’s National Vulnerability Database.

The bug is so critical in part because it requires few high-level technical skills to exploit, and would allow for an authentication bypass, meaning hackers can access affected devices without inputting proper username and password credentials. The issue affects Palo Alto Networks device users who rely on a verification technique called SAML authentication.

U.S. Cyber Command recently has warned of unrelated malicious activity from suspected North Korean hackers, and has sought to highlight Russian information operations aimed at propagating conspiracy theories in the U.S.

Hackers often will aim to exploit vulnerabilities before a patch is available, as they did when the BlueKeep security vulnerability in Microsoft’s Remote Desktop Protocol emerged in 2019. In that case, even when a security fix was released, the issue was so severe that some security teams told CyberScoop they were unable to vet the security update, and thus ensure it would function properly, before implementing the fix.

Latest Podcasts

Text extracted automatically; images, tables and formatting may be missing. Original: https://cyberscoop.com/cyber-command-palo-alto-networks-patch/