ZeroHour
Help Net Securitypublished ()ingested @zeljkazorz

2,000 Palo Alto Networks devices compromised in latest attacks

Vulnerabilities mentionedAll →

CVEVulnerabilityCVSSEPSSFlagsAffectedExposurePublished
CVE-2024-0012
+1 in the same advisory: …9474
Authentication Bypass in Palo Alto Networks PAN-OS Management Interface

CVE-2024-0012 is a critical authentication bypass (CWE-306) in the web management interface of Palo Alto Networks PAN-OS that lets an unauthenticated attacker with network access to that interface gain full PAN-OS administrator privileges. It is triggered simply by sending requests to an exposed management web interface, with no credentials or user interaction required. Once inside, the attacker can perform administrative actions, tamper with device configuration, and chain the bug with the related privilege escalation flaw CVE-2024-9474 for deeper compromise. Only PAN-OS 10.2, 11.0, 11.1 and 11.2 are affected; Cloud NGFW and Prisma Access are not, and risk is greatly reduced when the management interface is restricted to trusted internal IP addresses per vendor best practice. The flaw is being actively exploited: it was added to CISA KEV on 2024-11-18 with known ransomware use, and public reporting describes an ongoing campaign that has compromised more than 2,000 Palo Alto devices using this bug chained with CVE-2024-9474.

Do: Upgrade PAN-OS 10.2, 11.0, 11.1 and 11.2 deployments to the patched releases listed in the vendor advisory (security.paloaltonetworks.com/CVE-2024-0012), ensuring the chained privilege escalation bug CVE-2024-9474 is also addressed. Until patched, never expose the management web interface to untrusted networks or the internet, and restrict access to trusted internal IP addresses only. Review device logs and configurations for signs of compromise (unexpected admin activity or configuration changes) and hunt for persistence on any internet-exposed device.

9.3
group max
100% KEV ransomware PoC
  • Palo Alto Networks PAN-OS PAN-OS 10.2, 11.0, 11.1 and 11.2 (Cloud NGFW and Prisma Access are not impacted)
largetens of thousands of internet-exposed PAN-OS management interfaces, with 2,000+ devices already confirmed compromised
Full article542 words · extracted from helpnetsecurity.com · click to collapse

Attackers have compromised around 2,000 Palo Alto Networks firewalls by leveraging the two recently patched zero-days (CVE-2024-0012 and CVE-2024-9474), Shadowserver Foundation’s internet-wide scanning has revealed.

Compromised devices are predominantly located in the US and India, the nonprofit says.

Palo Alto firewalls compromised

Manual and automated scanning activity has been spotted

Approximately two weeks ago, Palo Alto Networks warned that attackers have been spotted leveraging a zero-day flaw to achieve remote code execution on vulnerable devices, and advised admins to make sure that access to the devices’ management interfaces was appropriately secured.

On Monday, the company confirmed that there were two zero-days under exploitation: CVE-2024-0012, which allows unauthenticated access to the interface in question, and CVE-2024-9474, which allows attackers to escalate their privileges on compromised Palo Alto Networks firewalls to root, and that attackers have been dropping webshells on them.

WatchTowr researchers followed that by publishing an analysis of how the two bugs can be used in concert and a Nuclei template that admins could leverage to check whether their devices are affected by them.

In the meantime, the attacks continued and Palo Alto thinks they may escalate.

“At this time, Unit 42 assesses with moderate to high confidence that a functional exploit chaining CVE-2024-0012 and CVE-2024-9474 is publicly available, which will enable broader threat activity,” the company’s incident responders have shared on Wednesday.

“Unit 42 has also observed both manual and automated scanning activity aligning with the timeline of third-party artifacts becoming widely available.”

Palo Alto Networks continues adding new indicators of compromise associated with these attacks.

The company has additionally revealed that the two vulnerabilities also affect its Panorama (firewall management) appliances, as well as its WildFire appliances, which are used for setting up sandbox systems to analyze suspicious files. (Those appliances are also running PAN-OS.)

Affected organizations are advised to check the security advisories for remediation guidance.

UPDATE (November 22, 2024, 02:20 p.m. ET):

“Arctic Wolf has observed multiple intrusions across a variety of industries involving Palo Alto Network firewall devices,” the company’s researchers shared today.

Based on the timing – the attacks started several hours after watchTowr published their analysis of the two vulnerabilities and explained how they can be exploited in tandem – and based on the names of some files observed in the attacks, “we assess with moderate confidence that these intrusions likely involved the exploitation of CVE-2024-0012 chained together with CVE-2024-9474 for initial access,” they said.

Following the initial compromise, in some instances the attackers tried to:

  • Download a Sliver C2 (command and control) implant
  • Exfiltrate data (firewall configuration files, mostly, but also operating system passwd and shadow files)
  • Deploy an obfuscated PHP webshell
  • Deploy the XMRig cryptocoin miner

UPDATE (November 23, 2024, 12:30 p.m. ET):

“Palo Alto Networks is actively investigating the scope of impact related to these vulnerabilities and is closely engaged with our customers to provide mitigation support as needed,” a company spokesperson told Help Net Security.

“While widespread exploit attempts were not observed until after the vulnerability was publicly disclosed on November 19th, we are actively helping customers who were unable to take mitigating action in time and require additional support.”

Subscribe to our breaking news e-mail alert to never miss out on the latest breaches, vulnerabilities and cybersecurity threats. Subscribe here!

Text extracted automatically; images, tables and formatting may be missing. Original: https://www.helpnetsecurity.com/2024/11/21/palo-alto-firewalls-compromised-cve-2024-0012-cve-2024-9474/