Palo Alto Networks has warned its customers to patch security vulnerabilities (with public exploit code) that could allow attackers to hijack firewalls.
See also: SonicWall: Critical vulnerability exploited by ransomware gangs

The firewall hijack vulnerabilities were discovered in Expedition , which helps migrate configurations from Checkpoint, Cisco, or other supported vendors.
They can be used to access sensitive data, such as user credentials, which can help take over firewall administrator accounts.
These bugs are a combination of command injection, cross-site scripting (XSS), cleartext storage of sensitive information, lack of authentication, and SQL injection vulnerabilities:
- CVE-2024-9463 (Unauthenticated Command Injection Vulnerability)
- CVE-2024-9464 (authentication injection vulnerability)
- CVE-2024-9465 (unauthenticated SQL injection vulnerability)
- CVE-2024-9466 (cleartext credentials stored in logs)
- CVE-2024-9467 (unauthenticated reflected XSS vulnerability)
See also: Hacker claims to have breached French telecoms provider SFR
Horizon3.ai researcher Zach Hanley , who found and reported four of the bugs, also published a written root cause analysis detailing how he found three of these flaws while researching the CVE-2024-5910 vulnerability (disclosed and patched in July), which allows attackers to reset the Expedition application's administrator credentials.

Hanley also released a proof-of-concept exploit that combines the CVE-2024-5910 administrator rollback flaw with the CVE-2024-9464 to gain “unverified” arbitrary command execution on vulnerable Expedition servers.
Palo Alto Networks says that, at this time, there is no evidence that the security flaws have been exploited in attacks.
See also: Palo Alto: Fixes critical vulnerability in Expedition Migration Tool
Firewall hijacking, such as Palo Alto, is a sophisticated cyberattack that involves gaining unauthorized control over a network’s firewall settings. Cybercriminals exploit vulnerabilities within the firewall to redirect, block, or monitor traffic between internal and external networks. This can lead to data breaches, unauthorized access, and potential service disruptions. By manipulating firewall rules, attackers can create backdoors for permanent access or bypass security measures entirely. To mitigate the risk of firewall hijacking, it is essential to keep your firewall software up to date, use strong authentication mechanisms, and regularly monitor network traffic and firewall configurations for any anomalies.
Source: bleepingcomputer
🔒 Protect your privacy with Proton VPN
Swiss VPN from the creators of Proton Mail — strict no-logs policy, strong encryption, and built-in NetShield that blocks ads, trackers, & malware.
- ✔ No-logs, based in Switzerland (except 14-Eyes)
- ✔ NetShield: blocks ads, trackers & malicious domains
- ✔ Covers all devices — free version available
The link is an affiliate link — SecNews may receive a commission at no additional cost to you. It does not affect the independence of our article writing.
