ZeroHour
The Hacker Newspublished ()ingested @TheHackersNews

CISA Warns of Critical Fortinet Flaw as Palo Alto and Cisco Issue Urgent Security Patches

Vulnerabilities mentionedAll →

CVEVulnerabilityCVSSEPSSFlagsAffectedExposurePublished
CVE-2024-20432
A vulnerability in the REST API and web UI of Cisco Nexus Dashboard Fabric Controller (NDFC) could allow an authenticated, low-privileged, remote attacker to pe

A vulnerability in the REST API and web UI of Cisco Nexus Dashboard Fabric Controller (NDFC) could allow an authenticated, low-privileged, remote attacker to perform a command injection attack against an affected device. This vulnerability is due to improper user authorization and insufficient validation of command arguments. An attacker could exploit this vulnerability by submitting crafted commands to an affected REST API endpoint or through the web UI. A successful exploit could allow the attacker to execute arbitrary commands on the CLI of a Cisco NDFC-managed device with network-admin privileges. Note: This vulnerability does not affect Cisco NDFC when it is configured for storage area network (SAN) controller deployment.

NVD description · AI analysis pending
8.81%
  • cisco nexus dashboard fabric controller
CVE-2024-23113
Format String Vulnerability Enables Unauthenticated RCE in Fortinet FortiOS and FortiProxy

CVE-2024-23113 is a use of externally-controlled format string (CWE-134) in multiple Fortinet products, allowing an unauthenticated remote attacker to execute unauthorized code or commands by sending specially crafted packets to an affected device. The flaw carries a critical CVSS 3.1 score of 9.8 (network vector, no privileges or user interaction required, high impact on confidentiality, integrity, and availability). It affects FortiOS 7.0.0 through 7.0.13, 7.2.0 through 7.2.6, and 7.4.0 through 7.4.2; FortiProxy 7.0.0 through 7.0.14, 7.2.0 through 7.2.8, and 7.4.0 through 7.4.2; FortiPAM 1.0.0 through 1.0.3, 1.1.0 through 1.1.2, and 1.2.0; and FortiSwitchManager 7.0.0 through 7.0.3 and 7.2.0 through 7.2.3. CISA added the vulnerability to the Known Exploited Vulnerabilities catalog on 2024-10-09 and warns it is likely being exploited in the wild, though no public proof-of-concept is known. Scanning coverage reported in the trade press indicates roughly 87,000 or more internet-exposed Fortinet devices remained vulnerable and open to attack after disclosure.

Do: Upgrade affected FortiOS, FortiProxy, FortiPAM, and FortiSwitchManager deployments to a patched release per Fortinet's advisory, since the data does not specify fixed build numbers. Until patching is complete, restrict management interface access to trusted sources, minimize internet exposure of affected devices, and verify your version falls within the affected ranges above. Treat this as an actively exploited vulnerability per CISA's KEV listing (added 2024-10-09) and prioritize it accordingly.

9.862% KEV
  • Fortinet FortiOS 7.4.0 through 7.4.2, 7.2.0 through 7.2.6, 7.0.0 through 7.0.13
  • Fortinet FortiProxy 7.4.0 through 7.4.2, 7.2.0 through 7.2.8, 7.0.0 through 7.0.14
  • Fortinet FortiPAM 1.2.0, 1.1.0 through 1.1.2, 1.0.0 through 1.0.3
  • +1 more
large≈87,000+ internet-exposed Fortinet devices per public scans (FortiOS/FortiProxy deployments; total installed base larger, affected-version share unknown)
CVE-2024-9463
+1 in the same advisory: …9465
Unauthenticated OS Command Injection in Palo Alto Networks Expedition

CVE-2024-9463 is a critical (CVSS 4.0: 9.9) OS command injection flaw (CWE-78) in Palo Alto Networks Expedition, the vendor's on-premises migration and firewall-management tool. An unauthenticated, network-adjacent attacker can send crafted input to trigger arbitrary operating system command execution with root privileges, requiring no credentials or user interaction. A successful compromise exposes the sensitive data Expedition holds for managed PAN-OS firewalls, including usernames, cleartext passwords, device configurations, and device API keys, which can enable follow-on attacks against the firewalls themselves. Any organization running an Expedition deployment, typically as a management appliance that is sometimes reachable from the internet, is affected. Exploitation is confirmed in the wild: Palo Alto Networks confirmed active exploitation (reported alongside SQL injection flaw CVE-2024-9465), CISA added it to the Known Exploited Vulnerabilities catalog on 2024-11-14, and EPSS assigns a 98.5% probability of exploitation within 30 days.

Do: Upgrade Expedition to the vendor-fixed release per Palo Alto Networks' advisory, and remove or restrict internet exposure of the Expedition web interface; if patching is not immediately possible, CISA's required action is to apply vendor mitigations or discontinue use of the product. Because exploitation can disclose cleartext firewall usernames, passwords, and API keys, rotate those credentials and review firewall configurations and Expedition logs for signs of compromise, particularly given confirmed active exploitation alongside CVE-2024-9465.

9.9
group max
99% KEV
  • Palo Alto Networks Expedition
nichelikely in the low thousands of on-premises deployments worldwide, with public scans showing only on the order of hundreds of internet-exposed instances
CVE-2024-9464
+2 in the same advisory: …9466 …9467
Authenticated OS Command Injection in Palo Alto Networks Expedition

CVE-2024-9464 is an OS command injection flaw (CWE-78) in Palo Alto Networks Expedition, the vendor's firewall migration and management tool, that lets an authenticated attacker inject and run arbitrary operating system commands with root privileges on the Expedition host. It is triggered over the network (AV:N) with only low privileges required, meaning any valid, authenticated Expedition session with crafted input, and it requires no user interaction or special conditions. Successful exploitation exposes the sensitive data Expedition stores during migrations, including usernames, cleartext passwords, device configurations, and API keys of managed PAN-OS firewalls. Any organization running Expedition is affected, typically those using the tool to migrate firewalls from other vendors to PAN-OS or to consolidate Panorama deployments. Palo Alto Networks and CISA have warned of active exploitation of Expedition vulnerabilities from this disclosure (CVE-2024-5910, CVE-2024-9463, CVE-2024-9465), related reporting indicates CISA has added the Expedition bugs to its Known Exploited Vulnerabilities catalog, and a very high EPSS score (82.6%, 100th percentile) indicates this flaw is highly likely to be exploited within 30 days.

Do: Update Expedition to the latest software/content release available from Palo Alto Networks per its advisory (no fixed version is specified in the source data), and restrict the Expedition web interface to trusted management networks or VPN-only access. Because Expedition stores PAN-OS firewall credentials, configurations, and API keys — potentially in cleartext — rotate those credentials and API keys and review Expedition logs for unexpected authenticated activity.

9.3
group max
83%
  • Palo Alto Networks Expedition (firewall migration/management tool)
moderate≈ a few thousand exposed deployments (low thousands of internet-reachable Expedition instances within a modest overall install base)
Full article644 words · extracted from thehackernews.com · click to collapse

Ravie LakshmananOct 10, 2024Vulnerability / Network Security

The U.S. Cybersecurity and Infrastructure Security Agency (CISA) on Wednesday added a critical security flaw impacting Fortinet products to its Known Exploited Vulnerabilities (KEV) catalog, citing evidence of active exploitation.

The vulnerability, tracked as CVE-2024-23113 (CVSS score: 9.8), relates to a case of remote code execution that affects FortiOS, FortiPAM, FortiProxy, and FortiWeb.

"A use of externally-controlled format string vulnerability [CWE-134] in FortiOS fgfmd daemon may allow a remote unauthenticated attacker to execute arbitrary code or commands via specially crafted requests," Fortinet noted in an advisory for the flaw back in February 2024.

As is typically the case, the bulletin is sparse on details related to how the shortcoming is being exploited in the wild, or who is weaponizing it and against whom.

In light of active exploitation, Federal Civilian Executive Branch (FCEB) agencies are mandated to apply the vendor-provided mitigations by October 30, 2024, for optimum protection.

Palo Alto Networks Discloses Critical Bugs in Expedition

The development comes as Palo Alto Networks disclosed multiple security flaws in Expedition that could allow an attacker to read database contents and arbitrary files, in addition to writing arbitrary files to temporary storage locations on the system.

"Combined, these include information such as usernames, cleartext passwords, device configurations, and device API keys of PAN-OS firewalls," Palo Alto Networks said in a Wednesday alert.

The vulnerabilities, which affect all versions of Expedition prior to 1.2.96, are listed below -

  • CVE-2024-9463 (CVSS score: 9.9) - An operating system (OS) command injection vulnerability that allows an unauthenticated attacker to run arbitrary OS commands as root
  • CVE-2024-9464 (CVSS score: 9.3) - An OS command injection vulnerability that allows an authenticated attacker to run arbitrary OS commands as root
  • CVE-2024-9465 (CVSS score: 9.2) - An SQL injection vulnerability that allows an unauthenticated attacker to reveal Expedition database contents
  • CVE-2024-9466 (CVSS score: 8.2) - A cleartext storage of sensitive information vulnerability that allows an authenticated attacker to reveal firewall usernames, passwords, and API keys generated using those credentials
  • CVE-2024-9467 (CVSS score: 7.0) - A reflected cross-site scripting (XSS) vulnerability that enables execution of malicious JavaScript in the context of an authenticated Expedition user's browser if that user clicks on a malicious link, allowing phishing attacks that could lead to Expedition browser session theft

The company credited Zach Hanley of Horizon3.ai for discovering and reporting CVE-2024-9464, CVE-2024-9465, and CVE-2024-9466, and Enrique Castillo of Palo Alto Networks for CVE-2024-9463, CVE-2024-9464, CVE-2024-9465, and CVE-2024-9467.

There is no evidence that the issues have ever been exploited in the wild, although it said steps to reproduce the problem are already in the public domain, courtesy of Horizon3.ai.

There are approximately 23 Expedition servers exposed to the internet, most of which are located in the U.S., Belgium, Germany, the Netherlands, and Australia. As mitigations, it's recommended to limit access to authorized users, hosts, or networks, and shut down the software when not in active use.

Cisco Fixes Nexus Dashboard Fabric Controller Flaw

Last week, Cisco also released patches to remediate a critical command execution flaw in Nexus Dashboard Fabric Controller (NDFC) that it said stems from an improper user authorization and insufficient validation of command arguments.

Tracked as CVE-2024-20432 (CVSS score: 9.9), it could permit an authenticated, low-privileged, remote attacker to perform a command injection attack against an affected device. The flaw has been addressed in NDFC version 12.2.2. It's worth noting that versions 11.5 and earlier are not susceptible.

"An attacker could exploit this vulnerability by submitting crafted commands to an affected REST API endpoint or through the web UI," it said. "A successful exploit could allow the attacker to execute arbitrary commands on the CLI of a Cisco NDFC-managed device with network-admin privileges."

Found this article interesting? Follow us on Google News, Twitter and LinkedIn to read more exclusive content we post.

Text extracted automatically; images, tables and formatting may be missing. Original: https://thehackernews.com/2024/10/cisa-warns-of-critical-fortinet-flaw-as.html