HomeSecurityHackers exploit vulnerability in Palo Alto firewalls

Hackers exploit vulnerability in Palo Alto firewalls

Attempts to exploit an authentication bypass vulnerability affecting Palo Alto Networks firewalls have begun just one day after the issue was publicly disclosed, threat intelligence firm GreyNoise reports , highlighting the speed with which cybercriminals are targeting new vulnerabilities.

See also: Palo Alto Networks fixes vulnerability in PAN-OS Software

Palo Alto vulnerability

Palo Alto Networks announced patches and mitigations for a critical vulnerability on February 12. The vulnerability in PAN-OS, codenamed CVE-2025-0108 , allows an unauthorized attacker to gain access to the firewall's management interface and execute specific PHP scripts

GreyNoise told SecurityWeek on February 13 that it had begun seeing attempts to exploit the CVE-2025-0108 vulnerability. According to the threat intelligence firm, as of the morning of February 14, exploit attempts from five separate IP addresses.

The exploit attempts have been labeled as "malicious" by GreyNoise, indicating that they likely originated from hackers rather than security researchers examining the extent of the vulnerable systems.

Assetnote , which discovered the vulnerability through its research team, published technical details about the issue shortly after Palo Alto announced patches and mitigations. This move may have made it easier for malicious actors to incorporate CVE-2025-0108 into their arsenal.

See also: Over 2,000 Palo Alto firewalls compromised via zero-day

On the other hand, Assetnote reported that CVE-2025-0108 requires combination with another vulnerability to achieve remote code execution.

Hackers exploit vulnerability in Palo Alto firewalls

CVE -2024-9474 is being actively exploited. Hackers may have either discovered a new vulnerability similar to CVE-2024-9474, or they may be targeting systems that have been unattended and unpatched for months. It is worth noting that CVE-2024-9474 was patched as early as November 2024.

Assetnote reported that CVE-2025-0108, while separate, is linked to CVE-2024-0012, an authentication bypass that has already been documented to be actively used, often in conjunction with CVE-2024-9474. It is possible that malicious actors modified the CVE-2024-0012 to target CVE-2025-0108, without needing the additional information published by the security firm.

See also: Palo Alto Networks patches two zero-day firewall vulnerabilities

Firewalls play a critical role in network security, acting as barriers that block unauthorized access while allowing legitimate traffic to pass through. However, vulnerabilities in firewalls can pose significant risks to systems and data. Misconfigurations are a common weakness, where inappropriate rules or settings create potential entry points for attackers. Additionally, outdated firewall software can leave systems exposed to known exploits, making timely updates essential. Regular monitoring, maintenance, and adherence to best practices are vital to mitigating these flaws and ensuring strong network protection.

Source: securityweek

Selecting the team

🔒 Protect your privacy with Proton VPN

Swiss VPN from the creators of Proton Mail — strict no-logs policy, strong encryption, and built-in NetShield that blocks ads, trackers, & malware.

  • ✔ No-logs, based in Switzerland (except 14-Eyes)
  • ✔ NetShield: blocks ads, trackers & malicious domains
  • ✔ Covers all devices — free version available
Try Proton VPN for free — 30-day money-back guarantee →

The link is an affiliate link — SecNews may receive a commission at no additional cost to you. It does not affect the independence of our article writing.

📧
Subscribe to the SecNews Newsletter

The most important Security & Technology news in your Inbox.

Absentee Mia
Absentee Miahttps://www.secnews.gr
Being your self, in a world that constantly tries to change you, is your greatest achievement

SEARCH

FOLLOW US

📧
Newsletter SecNews
The most important Security & Technology news in your inbox.

LIVE NEWS