ZeroHour
The Hacker Newspublished ()ingested @TheHackersNews

PAN-OS Firewall Vulnerability Under Active Exploitation

Vulnerabilities mentionedAll →

CVEVulnerabilityCVSSEPSSFlagsAffectedExposurePublished
CVE-2024-0012
+1 in the same advisory: …9474
Authentication Bypass in Palo Alto Networks PAN-OS Management Interface

CVE-2024-0012 is a critical authentication bypass (CWE-306) in the web management interface of Palo Alto Networks PAN-OS that lets an unauthenticated attacker with network access to that interface gain full PAN-OS administrator privileges. It is triggered simply by sending requests to an exposed management web interface, with no credentials or user interaction required. Once inside, the attacker can perform administrative actions, tamper with device configuration, and chain the bug with the related privilege escalation flaw CVE-2024-9474 for deeper compromise. Only PAN-OS 10.2, 11.0, 11.1 and 11.2 are affected; Cloud NGFW and Prisma Access are not, and risk is greatly reduced when the management interface is restricted to trusted internal IP addresses per vendor best practice. The flaw is being actively exploited: it was added to CISA KEV on 2024-11-18 with known ransomware use, and public reporting describes an ongoing campaign that has compromised more than 2,000 Palo Alto devices using this bug chained with CVE-2024-9474.

Do: Upgrade PAN-OS 10.2, 11.0, 11.1 and 11.2 deployments to the patched releases listed in the vendor advisory (security.paloaltonetworks.com/CVE-2024-0012), ensuring the chained privilege escalation bug CVE-2024-9474 is also addressed. Until patched, never expose the management web interface to untrusted networks or the internet, and restrict access to trusted internal IP addresses only. Review device logs and configurations for signs of compromise (unexpected admin activity or configuration changes) and hunt for persistence on any internet-exposed device.

9.3
group max
100% KEV ransomware PoC
  • Palo Alto Networks PAN-OS PAN-OS 10.2, 11.0, 11.1 and 11.2 (Cloud NGFW and Prisma Access are not impacted)
largetens of thousands of internet-exposed PAN-OS management interfaces, with 2,000+ devices already confirmed compromised
CVE-2024-5910
Unauthenticated Admin Account Takeover in Palo Alto Networks Expedition

CVE-2024-5910 is a missing authentication flaw (CWE-306) in Palo Alto Networks Expedition, a tool used to migrate, tune, and enrich firewall configurations. An attacker with network access to an Expedition instance can exploit the unauthenticated critical function to take over the Expedition admin account without any credentials. Once in control, the attacker can access configuration secrets, credentials, and other data imported into Expedition, and public research (horizon3.ai) shows it can be chained with other Expedition bugs for full system compromise. Any organization running Expedition — particularly instances reachable from the internet or shared networks — is affected. The flaw is actively exploited: it was added to CISA's Known Exploited Vulnerabilities catalog on 2024-11-07, carries a 91.8% EPSS exploitation probability, and is being exploited alongside related Expedition and firewall bugs (CVE-2024-9463, CVE-2024-9465).

Do: Apply the vendor's patched Expedition release per Palo Alto Networks' advisory; if the tool is no longer needed, decommission or discontinue it, as CISA permits. Until patched, restrict network access to Expedition to trusted management hosts and remove it from internet exposure. Check Expedition logs for signs of unauthorized admin access and rotate any credentials or secrets stored in the tool.

9.392% KEV PoC
  • Palo Alto Networks Expedition
nichelikely low thousands of deployments worldwide; unknown for internet-exposed instances
CVE-2024-9463
+1 in the same advisory: …9465
Unauthenticated OS Command Injection in Palo Alto Networks Expedition

CVE-2024-9463 is a critical (CVSS 4.0: 9.9) OS command injection flaw (CWE-78) in Palo Alto Networks Expedition, the vendor's on-premises migration and firewall-management tool. An unauthenticated, network-adjacent attacker can send crafted input to trigger arbitrary operating system command execution with root privileges, requiring no credentials or user interaction. A successful compromise exposes the sensitive data Expedition holds for managed PAN-OS firewalls, including usernames, cleartext passwords, device configurations, and device API keys, which can enable follow-on attacks against the firewalls themselves. Any organization running an Expedition deployment, typically as a management appliance that is sometimes reachable from the internet, is affected. Exploitation is confirmed in the wild: Palo Alto Networks confirmed active exploitation (reported alongside SQL injection flaw CVE-2024-9465), CISA added it to the Known Exploited Vulnerabilities catalog on 2024-11-14, and EPSS assigns a 98.5% probability of exploitation within 30 days.

Do: Upgrade Expedition to the vendor-fixed release per Palo Alto Networks' advisory, and remove or restrict internet exposure of the Expedition web interface; if patching is not immediately possible, CISA's required action is to apply vendor mitigations or discontinue use of the product. Because exploitation can disclose cleartext firewall usernames, passwords, and API keys, rotate those credentials and review firewall configurations and Expedition logs for signs of compromise, particularly given confirmed active exploitation alongside CVE-2024-9465.

9.9
group max
99% KEV
  • Palo Alto Networks Expedition
nichelikely in the low thousands of on-premises deployments worldwide, with public scans showing only on the order of hundreds of internet-exposed instances
Full article813 words · extracted from thehackernews.com · click to collapse

Palo Alto Networks has released new indicators of compromise (IoCs) a day after the network security vendor confirmed that a zero-day vulnerability impacting its PAN-OS firewall management interface has been actively exploited in the wild.

To that end, the company said it observed malicious activity originating from below IP addresses and targeting PAN-OS management web interface IP addresses that are accessible over the internet -

  • 136.144.17[.]*
  • 173.239.218[.]251
  • 216.73.162[.]*

The company, however, warned that these IP addresses may possibly represent "third-party VPNs with legitimate user activity originating from these IPs to other destinations."

Palo Alto Networks' updated advisory indicates that the flaw is being exploited to deploy a web shell on compromised devices, allowing threat actors to gain persistent remote access.

The vulnerability, which is yet to be assigned a CVE identifier, carries a CVSS score of 9.3, indicating critical severity. It allows for unauthenticated remote command execution.

According to the company, the vulnerability requires no user interaction or privileges to exploit, and its attack complexity has been deemed "low."

That said, the severity of the flaw drops to high (CVSS score: 7.5) should access to the management interface be restricted to a limited pool of IP addresses, in which case the threat actor will have to obtain privileged access to those IPs first.

On November 8, 2024, Palo Alto Networks began advising customers to secure their firewall management interfaces amid reports of a remote code execution (RCE) flaw. It has since been confirmed that the mysterious vulnerability has been abused against a "limited number" of instances.

There are currently no details on how the vulnerability came to light, the threat actors behind the exploitation, and the targets of these attacks. Prisma Access and Cloud NGFW products are not impacted by the flaw.

Patches for the vulnerability are yet to be released, making it imperative that users take immediate steps to secure access to the management interface, if not already.

The advisory comes as three different critical flaws in Palo Alto Networks Expedition (CVE-2024-5910, CVE-2024-9463, and CVE-2024-9465) have come under active exploitation, per the U.S. Cybersecurity and Infrastructure Security Agency (CISA). At this stage, there is no evidence to suggest that the activities are related.

Palo Alto Networks Releases Patches

Palo Alto Networks has officially released patches for a set of two flaws that have come under active exploitation in the wild, allowing attackers to elevate their privileges and perform malicious actions.

The vulnerabilities are listed below -

  • CVE-2024-9474 (CVSS score: 6.9) - A privilege escalation vulnerability in Palo Alto Networks PAN-OS software allows a PAN-OS administrator with access to the management web interface to perform actions on the firewall with root privileges
  • CVE-2024-0012 (CVSS score: 9.3) - An authentication bypass in Palo Alto Networks PAN-OS software enables an unauthenticated attacker with network access to the management web interface to gain PAN-OS administrator privileges to perform administrative actions, tamper with the configuration, or exploit other authenticated privilege escalation vulnerabilities like CVE-2024-9474

The aforementioned weaknesses have been patched in PAN-OS 10.1.14-h6, PAN-OS 10.2.12-h2, PAN-OS 11.0.6-h1, PAN-OS 11.1.5-h1, PAN-OS 11.2.4-h1, and all later PAN-OS versions. The fixes have also been extended to maintenance releases.

In a separate threat brief, Palo Alto Networks said it has observed threat activity originating from IP addresses known to proxy/tunnel traffic for anonymous VPN services, and that it's actively investigating the event, which it's tracking under the moniker Operation Lunar Peek.

"Observed post-exploitation activity includes interactive command execution and dropping malware, such as [PHP] web shells, on the firewall," it added.

The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has since added both the flaws to the Known Exploited Vulnerabilities (KEV) catalog, requiring Federal Civilian Executive Branch (FCEB) agencies to remediate them by December 9, 2024.

Additional Technical Details Released

Researchers from watchTowr have published more technical details about CVE-2024-0012 and CVE-2024-9474, revealing how the two flaws could be chained together to achieve command injection. A proof-of-concept (PoC) exploit is expected to be released next week so as to give administrators enough time to patch.

"This time it's due to those pesky backticks, combined with the super-complicated step of simply asking the server not to check our authentication via X-PAN-AUTHCHECK," it said. "It's amazing that these two vulnerabilities got into a production appliance, amazingly allowed via the hacked-together mass of shell script invocations that lurk under the hood of a Palo Alto appliance."

As of November 18, 2024, Censys said it has identified 13,324 publicly exposed next-generation firewall (NGFW) management interfaces, with 34% of these exposures located in the United States. That said, it's worth noting that not all of these exposed hosts are necessarily vulnerable.

(The story was updated after publication to include details of the patches and an analysis of the fix released by watchTowr.)

Found this article interesting? Follow us on Google News, Twitter and LinkedIn to read more exclusive content we post.

Text extracted automatically; images, tables and formatting may be missing. Original: https://thehackernews.com/2024/11/pan-os-firewall-vulnerability-under.html