Article Details

Scrape Timestamp (UTC): 2024-11-09 06:13:08.633

Source: https://thehackernews.com/2024/11/palo-alto-advises-securing-pan-os.html

Original Article Text

Click to Toggle View

Palo Alto Advises Securing PAN-OS Interface Amid Potential RCE Threat Concerns. Palo Alto Networks on Friday issued an informational advisory urging customers to ensure that access to the PAN-OS management interface is secured because of a potential remote code execution vulnerability. "Palo Alto Networks is aware of a claim of a remote code execution vulnerability via the PAN-OS management interface," the company said. "At this time, we do not know the specifics of the claimed vulnerability. We are actively monitoring for signs of any exploitation." In the interim, the network security vendor has recommended that users correctly configure the management interface in line with the best practices, and make sure that access to it is possible only via trusted internal IPs to limit the attack surface. It goes without saying that the management interface should not be exposed to the Internet. Some of the other guidelines to reduce exposure are listed below - The development comes a day after the U.S. Cybersecurity and Infrastructure Security Agency (CISA) added a now-patched critical security flaw impacting Palo Alto Networks Expedition to its Known Exploited Vulnerabilities (KEV) catalog, citing evidence of active exploitation. The vulnerability, tracked as CVE-2024-5910 (CVSS score: 9.3), relates to a case of missing authentication in the Expedition migration tool that could lead to an admin account takeover, and possibly gain access to sensitive data. While it's currently not known how it's being exploited in the wild, federal agencies have been advised to apply the necessary fixes by November 28, 2024, to secure their networks against the threat.

Daily Brief Summary

CYBERCRIME // Palo Alto Warns of Potential Remote Execution Vulnerability

Palo Alto Networks issued an advisory about a potential remote code execution vulnerability in the PAN-OS management interface.

The company is currently unaware of the specifics but is monitoring for any signs of exploitation.

Users are advised to secure access to the management interface and allow connection only from trusted internal IPs.

The advisory follows recent action by CISA, who added another Palo Alto vulnerability to its Known Exploited Vulnerabilities catalog.

This separate vulnerability, CVE-2024-5910, was identified in the Expedition migration tool with a high severity score and potential for admin account takeover.

Federal agencies are required to apply the necessary patches for CVE-2024-5910 by November 28, 2024, to mitigate risks.

Best practices for securing interfaces include not exposing them to the open internet and following Palo Alto’s configuration guidelines.

The incident underlines the ongoing challenges and importance of securing network management interfaces against growing cybersecurity threats.