Palo Alto Networks is patching two zero-day vulnerabilities affecting its Next-Generation Firewalls (NGFW) that have been used in attacks.

The first vulnerability is tracked as CVE-2024-0012 and allows authentication bypass. It is located in the PAN-OS management web interface and attackers can exploit it remotely to gain administrative privileges, without requiring authentication or user interaction.
See also: Apache HertzBeat vulnerability allows exploitation of sensitive data
The second vulnerability is tracked as CVE-2024-9474 and allows privilege escalation. It allows malicious PAN-OS administrators to perform actions on the firewall with root privileges.
The CVE-2024-9474 vulnerability has now been disclosed, but the company had been warning about CVE-2024-0012 since November 8. It had told customers at the time to restrict access to next-generation firewalls, due to a potential RCE bug.
"Palo Alto Networks has observed activity exploiting vulnerabilities against a limited number of management web interfaces exposed to internet traffic originating outside the network," the company warned of both zero-day vulnerabilities.
See also: Botnet exploits zero-day vulnerability in GeoVision
“Palo Alto Networks has been actively monitoring and working with customers to identify and further mitigate the very small number of PAN-OS devices with management web interfaces that are exposed to the Internet or other untrusted networks,” it added in a separate report providing indicators of compromise.
While the company says these vulnerabilities only affect a "very small number" of firewalls, threat monitoring platform Shadowserver reported on Friday that it is monitoring more than 8,700 exposed PAN-OS management interfaces.
Macnica threat researcher Yutaka Sejiyamaalso told BleepingComputer that he found over 11,000 IP addresses running Palo Alto PAN-OS management interfaces exposed online.

The US cybersecurity agency, CISA, has already added CVE-2024-0012 and CVE-2024-9474 to the List of Known Exploitable Vulnerabilities and ordered federal agencies to patch their systems by December 9.
See also: Samba AD vulnerability allows hackers to escalate privileges
Protection from vulnerabilities
Organizations should apply security updates as soon as they are released, use multi-factor authentication (MFA) whenever possible, and replace equipment that is no longer receiving security patches, as this equipment will be vulnerable to vulnerabilities that are not going to be fixed.
It is also recommended to implement the Zero Trust.
Source: www.bleepingcomputer.com
