ZeroHour
Infosecurity Magazinepublished ()ingested Phil Muncaster

Palo Alto Networks and SonicWall Firewalls Under Attack

Vulnerabilities mentionedAll →

CVEVulnerabilityCVSSEPSSFlagsAffectedExposurePublished
CVE-2024-53704
Authentication Bypass in SonicWall SonicOS SSLVPN

CVE-2024-53704 is a critical (CVSS 9.8) improper authentication flaw (CWE-287) in the SSLVPN authentication mechanism of SonicWall's SonicOS. A remote, unauthenticated attacker can exploit it over the network without user interaction, bypassing SSLVPN authentication to gain unauthorized access to the VPN and a foothold into protected internal networks. CISA notes known ransomware use, making this a high-value entry point for follow-on attacks. Any organization running SonicWall SonicOS with SSLVPN enabled is affected. Exploitation is confirmed in the wild: CISA added the flaw to the Known Exploited Vulnerabilities catalog on 2025-02-18, public scans show 5,000+ internet-exposed SonicWall firewalls still unpatched, and EPSS rates the 30-day exploitation probability at 95.1%.

Do: Upgrade affected SonicOS deployments to the patched releases listed in SonicWall's advisory, prioritizing internet-facing SSLVPN endpoints. Until patched, restrict or disable SSLVPN exposure where feasible and hunt for signs of exploitation, since ransomware use is known. Remediation must satisfy CISA KEV required actions (apply vendor mitigations or discontinue use).

9.895% KEV ransomware
  • SonicWall SonicOS
largeestimated tens of thousands of SSLVPN-enabled SonicWall firewall deployments, with at least ~5,000 confirmed still exposed and unpatched on the public internet
CVE-2025-0108
Authentication Bypass in Palo Alto Networks PAN-OS Management Interface

CVE-2025-0108 is a missing-authentication flaw (CWE-306) in the PAN-OS management web interface of Palo Alto Networks firewalls that lets an unauthenticated attacker with network access to that interface bypass login and invoke certain PHP scripts, reportedly via path-confusion tricks in the web server stack. Invoking the scripts does not yield remote code execution, but it can compromise the confidentiality and integrity of PAN-OS, such as by reading or modifying management-plane information. Any PAN-OS firewall whose management web interface is reachable by an attacker — for example, exposed to the internet or reachable from a compromised internal network — is affected, while Cloud NGFW and Prisma Access are not. The flaw is being actively exploited: CISA added it to the Known Exploited Vulnerabilities catalog on 2025-02-18, a public proof-of-concept is available, EPSS puts the 30-day exploitation probability at 98.5%, and headlines report attackers chaining this bug with other PAN-OS flaws to breach firewalls.

Do: Upgrade PAN-OS to a fixed release per the Palo Alto Networks advisory (security.paloaltonetworks.com/CVE-2025-0108), since the vendor has patched the flaw. Until patched, restrict management web interface access to trusted internal IP addresses or management-only network zones as recommended in the vendor's hardening guidance. Check management-interface logs for unauthenticated requests to PHP scripts and for signs of chaining with other recently exploited PAN-OS vulnerabilities.

8.898% KEV PoC ×3
  • Palo Alto Networks PAN-OS
large≈ tens of thousands of internet-exposed PAN-OS management interfaces (subset of a much larger firewall install base)
Full article420 words · extracted from infosecurity-magazine.com · click to collapse

Palo Alto Networks and SonicWall customers are being advised to patch their products, after it emerged that threat actors are actively exploiting vulnerabilities in both.

SonicWall first detailed authentication bypass bug CVE-2024-53704 in a security update on January 7. It impacts the firm’s SonicOS, which powers various firewall devices.

“An improper authentication vulnerability in the SSL VPN authentication mechanism allows a remote attacker to bypass authentication,” it warned of the CVSS 8.2-rated vulnerability.

The vendor’s security advisory was updated last week with a warning that proof-of-concepts (PoCs) for the vulnerability are now publicly available.

“This significantly increases the risk of exploitation,” it said. “Customers must immediately update all unpatched firewalls (7.1.x & 8.0.0). If applying the firmware update is not possible, disable SSLVPN. For further assistance, please contact SonicWall support.”

Read more on firewall threats: Fortinet Confirms Critical Zero-Day Vulnerability in Firewalls

Towards the end of the week. At least one security vendor said it had seen signs of exploitation in the wild.

“The released PoC exploit allows an unauthenticated threat actor to bypass MFA, disclose private information, and interrupt running VPN sessions,” noted Arctic Wolf. “Historically, threat actors have leveraged authentication bypass vulnerabilities on firewall and VPN gateways to deploy ransomware.”

Separately, threat actors also appear to be targeting firewalls from Palo Alto Networks.

The vendor released a security update on February 12, detailing how CVE-2025-0108 impacts the PAN-OS management web interface.

“An authentication bypass in the Palo Alto Networks PAN-OS software enables an unauthenticated attacker with network access to the management web interface to bypass the authentication otherwise required by the PAN-OS management web interface and invoke certain PHP scripts,” it explained.

“While invoking these PHP scripts does not enable remote code execution, it can negatively impact integrity and confidentiality of PAN-OS.”

Time for an Upgrade

Although workarounds are available, Palo Alto urged customers to upgrade to a supported, fixed version of the product.

While the vendor claimed at the time of its security update it was “not aware of any malicious exploitation of this issue,” security researchers warned of new threat activity late last week. At the time of writing, at least 20 observed IPs were trying to exploit the vulnerability in attacks, according to GreyNoise.

Edge devices like firewalls are increasingly popular targets for attack, given their location at the gateway to trusted networks.

Earlier this month, GCHQ’s National Cyber Security Centre (NCSC) and allies in Australia, Canada, New Zealand and the US published new guidance for edge device manufacturers, designed to improve security standards.

Text extracted automatically; images, tables and formatting may be missing. Original: https://www.infosecurity-magazine.com/news/palo-alto-networks-sonicwall/