Close Menu
  • Home
  • Articles
    • Attacks
      • BEC
      • Data Breach
      • DDoS
      • Evasion Attacks
      • Injection
      • Malware
      • MITM
      • Phishing
      • Ransomware
      • RCE
      • Social Engineering
      • Spoofing
      • Spyware
    • Business and Policy
      • BCP and DRP
      • GRC
      • Regulations
    • Data Protection
      • DLP
      • DRM
      • Encryption
      • IAM
    • Future, Trends and Insight
      • AI
      • Events & Community
      • Emerging Tech
      • Expert Panel
      • Interviews With Experts
      • Insights
      • Study & Research
    • Resources
      • Guides
      • Tools
      • Training & Education
    • Security
      • API
      • Apps
      • Cloud
      • Critical Infrastructure
      • Endpoint
      • Hardware
      • IoT
      • Mobile
      • Network
      • OT
      • Port Security
      • Security Architecture
      • Software Development
      • Supply Chain
      • Zero Trust
    • Threats and Vulnerabilities
      • Emerging Threats
      • Insider Threats
      • Risk Management
      • Threat Intelligence
      • Zero Day
  • News and Exclusives
    • Latest News
    • ISB Exclusive
    • Positive News
  • Who We Are
    • About Us
    • Information Security Buzz Expert Panel​
    • Write for Us
    • Media Pack
  • Contact Us
  • Newsletter
Facebook X (Twitter) LinkedIn
Facebook X (Twitter) LinkedIn
Information Security BuzzInformation Security Buzz
  • Home
  • Articles
    • Attacks
      • BEC
      • Data Breach
      • DDoS
      • Evasion Attacks
      • Injection
      • Malware
      • MITM
      • Phishing
      • Ransomware
      • RCE
      • Social Engineering
      • Spoofing
      • Spyware
    • Business and Policy
      • BCP and DRP
      • GRC
      • Regulations
    • Data Protection
      • DLP
      • DRM
      • Encryption
      • IAM
    • Future, Trends and Insight
      • AI
      • Events & Community
      • Emerging Tech
      • Expert Panel
      • Interviews With Experts
      • Insights
      • Study & Research
    • Resources
      • Guides
      • Tools
      • Training & Education
    • Security
      • API
      • Apps
      • Cloud
      • Critical Infrastructure
      • Endpoint
      • Hardware
      • IoT
      • Mobile
      • Network
      • OT
      • Port Security
      • Security Architecture
      • Software Development
      • Supply Chain
      • Zero Trust
    • Threats and Vulnerabilities
      • Emerging Threats
      • Insider Threats
      • Risk Management
      • Threat Intelligence
      • Zero Day
  • News and Exclusives
    • Latest News
    • ISB Exclusive
    • Positive News
  • Who We Are
    • About Us
    • Information Security Buzz Expert Panel​
    • Write for Us
    • Media Pack
  • Contact Us
  • Newsletter
Subscribe
Information Security BuzzInformation Security Buzz
Home - Threats and Vulnerabilities - Palo Alto Networks Warns of Exploitable Firewall Hijack Vulnerabilities
Threats and Vulnerabilities Latest News News & Analysis Threat Intelligence

Palo Alto Networks Warns of Exploitable Firewall Hijack Vulnerabilities

Kirsten DoyleBy Kirsten DoyleOctober 10, 2024Updated:November 8, 20243 Mins Read
Share LinkedIn Twitter Facebook Copy Link Email
Firewall Hijack
Share
Facebook Twitter LinkedIn Email Copy Link
Quick AI Summary
ChatGPTClaudeGeminiGrokPerplexityDeepSeekCopilot

Palo Alto Networks has issued an urgent advisory for its customers following the discovery of multiple critical vulnerabilities in its Expedition tool, which assists with firewall configuration migration.

The vulnerabilities are as follows:

CVE-2024-9463 has a score of 9.9. It’s an OS command injection vulnerability in Palo Alto Networks Expedition which allows an unauthenticated attacker to run arbitrary OS commands as root in Expedition, resulting in disclosure of usernames, cleartext passwords, device configurations, and device API keys of PAN-OS firewalls.

CVE-2024-9464, with 9.3 is a OS command injection vulnerability that allows a bad actor to run arbitrary OS commands as root in Expedition, resulting in disclosure of usernames, cleartext passwords, device configurations, and device API keys of PAN-OS firewalls.

CVE-2024-9465 has a 9.2 severity. this is a SQL injection vulnerability that enables a malefactor to reveal Expedition database contents, such as password hashes, usernames, device configurations, and device API keys. With this, attackers can also create and read arbitrary files on the Expedition system.

CVE-2024-9466 (8.2),  cleartext storage of sensitive information vulnerability allows a malicious actor to reveal firewall usernames, passwords, and API keys generated using those credentials.

CVE-2024-9467, with 7.0, is a reflected XSS vulnerability that enables execution of malicious JavaScript in the context of an authenticated Expedition user’s browser if that user clicks on a malicious link, allowing phishing attacks that could lead to Expedition browser session theft.

Horizon3.ai’s root cause analysis highlighted that the flaws enable attackers to escalate from these vulnerabilities to a full system compromise.

Immediate Patching Advised

Palo Alto Networks strongly recommends that all customers upgrade Expedition to version 1.2.96 or later, where patches for these vulnerabilities have been implemented. The upgrade process will also automatically address the cleartext storage issue (CVE-2024-9466) by removing affected files. Furthermore, the advisory recommends rotating all Expedition and PAN-OS firewall credentials after applying the update as a precaution.

For those who cannot immediately update, Palo Alto Networks advises restricting Expedition access to authorized users and limiting network exposure. While there is currently no evidence of active exploitation of these vulnerabilities, the availability of public exploit code underscores the urgency for organizations to secure their systems promptly.

Not the First Critical Vulnerability

This isn’t the first critical vulnerability Palo Alto has had to disclose this year. In April, the company detailed an actively exploited vulnerability in PAN-OS, tracked as CVE-2024-3400, with a CVSS score of 10.0.

The vulnerability stemmed from two combined bugs in PAN-OS. The first issue involved the GlobalProtect service, which failed to adequately validate session ID formats before storing them, allowing malefactors to save an empty file with a chosen filename. The second bug, which assumes these files are system-generated, uses the filenames in commands. While each bug alone isn’t highly damaging, together they enable unauthenticated remote shell command execution.

“A highly sophisticated threat actor discovered that by uniquely combining the two bugs, they could perform a two-stage attack to achieve command execution on the vulnerable device, the company said at the time.

The threat actor UTA0218 has leveraged these bugs in “Operation MidnightEclipse,” using crafted requests and a backdoor called UPSTYLE to execute commands and deploy reverse proxy tools like GOST.

For detailed technical information and remediation steps, Palo Alto Networks has provided an advisory on its security site, and additional analysis is available from Horizon3.ai, who conducted the initial investigation.

For more details on this advisory, visit the Palo Alto Networks advisory and Horizon3.ai’s root cause analysis.

Kirsten Doyle
Kirsten Doyle
Information Security Buzz News Editor

Kirsten Doyle has been in the technology journalism and editing space for nearly 24 years, during which time she has developed a great love for all aspects of technology, as well as words themselves. Her experience spans B2B tech, with a lot of focus on cybersecurity, cloud, enterprise, digital transformation, and data centre. Her specialties are in news, thought leadership, features, white papers, and PR writing, and she is an experienced editor for both print and online publications.

  • Kirsten Doyle
    Palo Alto warns of active exploitation of GlobalProtect authentication bypass flaw
  • Kirsten Doyle
    CrowdStrike, Google, and Shadowserver Foundation disrupt Glassworm botnet
  • Kirsten Doyle
    Threat Actors Deploy Tiflux RMM for Persistent Remote Access
  • Kirsten Doyle
    Major US telecom providers debut C2 ISAC to counter AI-driven threats

The opinions expressed in this post belong to the individual contributors and do not necessarily reflect the views of Information Security Buzz.

Share. Facebook Twitter LinkedIn Email Copy Link

Related Posts

Palo Alto warns of active exploitation of GlobalProtect authentication bypass flaw

June 2, 20263 Mins Read

How EM is boosting the career trajectory of VM analysts

May 19, 20266 Mins Read

Microsoft patches 138 vulnerabilities as AI-driven discovery accelerates

May 14, 20265 Mins Read
ISB-Bora-Side-Bar

No se ha podido establecer conexión. Error 429

 
ISB-Bora-Side-Bar
Black ISB Logo

Information Security Buzz is an independent resource that provides the experts’ comments, analysis, and opinion on the latest Cybersecurity news and topics

X (Twitter) LinkedIn Facebook RSS

Working With Us

  • About Us
  • Advertise With Us
  • Contact Us

Write For Us

  • How To Contribute

The Pages

  • Privacy Policy
  • Cookie Policy
  • AI Policy
  • Terms & Conditions
  • Copyright Notice

Information Security Buzz and all its contents are copyright © 2014-2025. All rights reserved. All third-party trademarks are recognized.

Type above and press Enter to search. Press Esc to cancel.

Manage Consent
To provide the best experiences, we use technologies like cookies to store and/or access device information. Consenting to these technologies will allow us to process data such as browsing behavior or unique IDs on this site. Not consenting or withdrawing consent, may adversely affect certain features and functions.
Functional Always active
The technical storage or access is strictly necessary for the legitimate purpose of enabling the use of a specific service explicitly requested by the subscriber or user, or for the sole purpose of carrying out the transmission of a communication over an electronic communications network.
Preferences
The technical storage or access is necessary for the legitimate purpose of storing preferences that are not requested by the subscriber or user.
Statistics
The technical storage or access that is used exclusively for statistical purposes. The technical storage or access that is used exclusively for anonymous statistical purposes. Without a subpoena, voluntary compliance on the part of your Internet Service Provider, or additional records from a third party, information stored or retrieved for this purpose alone cannot usually be used to identify you.
Marketing
The technical storage or access is required to create user profiles to send advertising, or to track the user on a website or across several websites for similar marketing purposes.
  • Manage options
  • Manage services
  • Manage {vendor_count} vendors
  • Read more about these purposes
View preferences
  • {title}
  • {title}
  • {title}