THREAT LEVEL - HIGH

26-11-2024

Two Critical Vulnerabilities in Palo Alto PAN-OS Actively Exploited

Threat Level Description

IthacaLabs has maintained the Threat Level: High – An attack is highly likely. Addressing the broad nature of the threat in order to reach an acceptable risk level, requires additional and sustainable protective security measures combined with specific business and geographical vulnerabilities and judgments.

Description

We have observed that two critical vulnerabilities impacting Palo Alto Networks PAN-OS have been identified.

An attacker, by exploiting these vulnerabilities, could gain unauthorized access to system resources and execute arbitrary commands with root privileges.

The vulnerability, tracked as CVE-2024-0012, is an authentication bypass in the Palo Alto Networks PAN-OS software. This flaw allows remote attackers, with network access to the management web interface, to gain PAN-OS administrator privileges without requiring authentication or user interaction.

The vulnerability, tracked as CVE-2024-9474, is a privilege escalation flaw in PAN-OS. It enables malicious administrators of PAN-OS, with access to the management web interface, to perform actions on the firewall with root privileges.

Palo Alto Networks has confirmed that these vulnerabilities have been actively exploited in the wild. They were used to deploy web shells on compromised devices, granting attackers persistent remote access.

Note that Cloud NGFW and Prisma Access are not impacted by this vulnerability.

Affected Products:

PAN-OS:

  • PAN-OS 11.2 Versions <11.2-h1
  • PAN-OS 11.1 Versions <11.1.5-h1
  • PAN-OS 11.0 Versions <11.0.6-h1
  • PAN-OS 10.2 Versions <10.2.12-h2
  • PAN-OS 10.1 Versions <10.1.14-h6

Recommendation(s):

You should proceed to apply all security patches provided by the vendor immediately.

Furthermore, you should consider restricting access to the management interface to trusted internal IP addresses only, preventing unauthorized external access from the internet.

You should understand the importance of security updates, and the urgency with which they should be applied, no matter how large or small your organization is. It is very important to apply an efficient patch management solution and always have enabled an active event security logging and practice event monitoring. To protect the valuable assets of your business and be compliant with the relevant industry regulations requires a comprehensive approach to the management of risk, including Penetration Testing at least annually and upon significant changes.

References:

SIGN UP

Get the latest Threat Alerts in your inbox.