HomeSecurityCISA: Added Palo Alto Networks vulnerability to the KEV List

CISA: Added Palo Alto Networks vulnerability to KEV List

CISA added a vulnerability in the migration tool, Palo Alto Networks Expedition , to the KEV List.

Palo Alto Networks CISA vulnerability

The agency warned that cybercriminals are exploiting the critical authentication vulnerability, tracked as CVE-2024-5910. It was patched in July and threat actors can remotely exploit it to reset application admin credentials on Expedition servers exposed to the Internet.

“ Palo Alto Expedition contains a vulnerability that could allow an attacker with network access to take control of an Expedition admin account and gain access to configuration secrets, credentials, and other data ,” CISA says

See also: CISA warns of vulnerabilities in PTZOptics cameras

The cybersecurity agency did not provide further details about these attacks. However, Horizon3.ai researcher Zach Hanley released a proof-of-concept exploit in October that can help combine this vulnerability with CVE-2024-9464 (command injection – patched last month) to execute unauthorized commands on vulnerable Expedition servers.

The CVE-2024-9464 vulnerability can be combined with other bugs (also patched by Palo Alto Networks in October) to allow attackers to take control of firewall admin accounts and compromise PAN-OS firewalls.

Administrators who cannot immediately install security updatesare urged to restrict Expedition network access to authorized users, computers, or networks only.

“All Expedition usernames, passwords , and API keys will need to be rotated after upgrading to the stable version of Expedition. All firewall usernames, passwords, and API keys, which are processed by Expedition, will need to be rotated after the update,” the company warns.

See also: Google warns of Android vulnerability exploitation

CISA said that US federal agencies must secure vulnerable Palo Alto Networks Expedition servers within three weeks, specifically by November 28 .

KEV catalog

While CISA's KEV list is primarily designed to alert federal agencies, all organizations should prioritize patching this vulnerability.

The KEV catalog is very useful for organizations around the world who want to learn about new threats and are interested in better vulnerability management and prioritization.

Overall, CISA is a great help in protecting and addressing cybersecurity threats. This organization works with various sectors, such as private businesses, governments , and local authorities, to improve the security of digital systems.

See also: Researchers uncover six vulnerabilities in Ollama AI framework

Selecting the team

🔒 Protect your privacy with Proton VPN

Swiss VPN from the creators of Proton Mail — strict no-logs policy, strong encryption, and built-in NetShield that blocks ads, trackers, & malware.

  • ✔ No-logs, based in Switzerland (except 14-Eyes)
  • ✔ NetShield: blocks ads, trackers & malicious domains
  • ✔ Covers all devices — free version available
Try Proton VPN for free — 30-day money-back guarantee →

The link is an affiliate link — SecNews may receive a commission at no additional cost to you. It does not affect the independence of our article writing.

It provides information and tools to help organizations protect their networks from cyberattacks and respond to any attacks that may occur. It also informs the public about any vulnerabilities in widely used systems and applications.

Overall, CISA's role is vital to protecting the digital infrastructure of the US and other regions.

Source: www.bleepingcomputer.com

📧
Subscribe to the SecNews Newsletter

The most important Security & Technology news in your Inbox.

Digital Fortress
Digital Fortresshttps://www.secnews.gr
Pursue Your Dreams & Live!

SEARCH

FOLLOW US

📧
Newsletter SecNews
The most important Security & Technology news in your inbox.

LIVE NEWS