Close Menu
Indo Guard OnlineIndo Guard Online
  • Home
  • Cyber Security
  • Risk Management
  • Travel
  • Security News
  • Tech
  • More
    • Data Privacy
    • Data Protection
    • Global Security
What's Hot

Safe Coding Vibe: Full New Guide

June 19, 2025

Bluenoroff Deepfake Zoom AFM Hits Crypto employee with malicious MacOS software

June 19, 2025

Discover the areas hiding in trusted instruments – find out how in this free expert session

June 19, 2025
Facebook X (Twitter) Instagram
Facebook X (Twitter) Instagram YouTube
Indo Guard OnlineIndo Guard Online
Subscribe
  • Home
  • Cyber Security
  • Risk Management
  • Travel
  • Security News
  • Tech
  • More
    • Data Privacy
    • Data Protection
    • Global Security
Indo Guard OnlineIndo Guard Online
Home » Major vulnerabilities are fixed in SonicWall, Palo Alto Expedition and Aviatrix controllers
Global Security

Major vulnerabilities are fixed in SonicWall, Palo Alto Expedition and Aviatrix controllers

AdminBy AdminJanuary 9, 2025No Comments4 Mins Read
Share
Facebook Twitter LinkedIn Pinterest Email Copy Link


January 9, 2025Ravi LakshmananEndpoint Vulnerability / Security

Palo Alto Networks has released software patches to address several security flaws in its Expedition migration tool, including a high-severity flaw that an authenticated attacker could use to gain access to sensitive data.

“Several vulnerabilities in the Palo Alto Networks Expedition migration tool could allow an attacker to read the contents of the Expedition database and arbitrary files, and to create and delete arbitrary files on the Expedition system,” the company said in a statement. said in the advisory.

“These files include information such as usernames, plaintext passwords, device configurations, and device API keys for firewalls running PAN-OS software.”

Cyber ​​security

Expedition, a free tool offered by Palo Alto Networks to facilitate migration from third-party firewall vendors to its own platform, has reached end-of-life (EoL) as of December 31, 2024. The list of disadvantages is as follows –

  • CVE-2025-0103 (CVSS Score: 7.8) – SQL injection vulnerability that could allow an authenticated attacker to expose the contents of the Expedition database, such as password hashes, usernames, device configurations, and device API keys, and to create and read arbitrary files
  • CVE-2025-0104 (CVSS Score: 4.7) – A cross-site scripting (XSS) vulnerability that allows attackers to execute malicious JavaScript code in the context of an authenticated user’s browser when that authenticated user clicks on a malicious link that allows phishing attacks and could lead to browser-theft session
  • CVE-2025-0105 (CVSS Score: 2.7) – Arbitrary file deletion vulnerability that allows an unauthenticated attacker to delete arbitrary files accessible by user www-data on the host’s file system
  • CVE-2025-0106 (CVSS Score: 2.7) – Wildcard extension vulnerability allows an unauthenticated attacker to list files on the host’s file system
  • CVE-2025-0107 (CVSS Score: 2.3) – Operating system (OS) command injection vulnerability that allows an authenticated attacker to execute arbitrary OS commands as the www-data user in Expedition, resulting in the disclosure of usernames, plaintext passwords, device configurations, and keys Device API for firewalls running PAN-OS software

Palo Alto Networks said the vulnerabilities were fixed in versions 1.2.100 (CVE-2025-0103, CVE-2025-0104 and CVE-2025-0107) and 1.2.101 (CVE-2025-0105 and CVE-2025-0106 ). ), and that it does not intend to release any additional updates or security fixes.

As a workaround, it is recommended to ensure that network access to Expedition is restricted to authorized users, hosts, and networks, or to close the service when not in use.

SonicWalls releases SonicOS patches

Development coincides with SonicWall patches to deliver to fix multiple flaws in SonicOS, two of which can be used to achieve authentication bypass and privilege escalation, respectively −

  • CVE-2024-53704 (CVSS Score: 8.2) – Misauthentication vulnerability in the SSLVPN authentication mechanism that allows a remote attacker to bypass authentication.
  • CVE-2024-53706 (CVSS Score: 7.8) – Vulnerability in the Gen7 SonicOS NSv cloud platform (AWS and Azure versions only) that allows a remote local attacker with low authentication privileges to elevate the privileges of root and potentially lead to code execution.
Cyber ​​security

While there is no evidence that any of the aforementioned vulnerabilities have been exploited in the wild, it is imperative that users take steps to apply the latest patches as soon as possible.

Details about a critical flaw in the Aviatrix controller

The updates also come after Polish cybersecurity company Securing detailed a maximum severity security flaw affecting the Aviatrix controller (CVE-2024-50603, CVSS score: 10.0) that could be used to execute arbitrary code. This affects versions 7.x through 7.2.4820.

A flaw rooted in the fact that some code segments in the API endpoint did not sanitize user-supplied parameters (“list_flightpath_destination_instances” and “flightpath_connection_test”) was fixed in version 7.1.4191 or 7.2.4996.

“Due to improper neutralization of special elements used in the OS command, an unauthenticated attacker can remotely execute arbitrary code,” security researcher Jakub Karepta said.

Did you find this article interesting? Follow us Twitter  and LinkedIn to read more exclusive content we publish.





Source link

Share. Facebook Twitter Pinterest LinkedIn Tumblr Email Copy Link
Admin
  • Website

Related Posts

Safe Coding Vibe: Full New Guide

June 19, 2025

Bluenoroff Deepfake Zoom AFM Hits Crypto employee with malicious MacOS software

June 19, 2025

Discover the areas hiding in trusted instruments – find out how in this free expert session

June 19, 2025

Russian APT29 operates Gmail app passwords to get around 2FA in the target phishing campaign

June 19, 2025

Meta adds support to logy for Android and iOS users

June 19, 2025

Linux’s new drawbacks provide complete root access via PAM and Udisks in major distributions

June 19, 2025
Add A Comment
Leave A Reply Cancel Reply

Loading poll ...
Coming Soon
Do You Like Our Website
: {{ tsp_total }}

Subscribe to Updates

Get the latest security news from Indoguardonline.com

Latest Posts

Safe Coding Vibe: Full New Guide

June 19, 2025

Bluenoroff Deepfake Zoom AFM Hits Crypto employee with malicious MacOS software

June 19, 2025

Discover the areas hiding in trusted instruments – find out how in this free expert session

June 19, 2025

Russian APT29 operates Gmail app passwords to get around 2FA in the target phishing campaign

June 19, 2025

Meta adds support to logy for Android and iOS users

June 19, 2025

Linux’s new drawbacks provide complete root access via PAM and Udisks in major distributions

June 19, 2025

The new malicious company uses Cloudflare tunnels to deliver rats through phishing networks

June 18, 2025

1500+ Minecraft players infected with malicious Java software

June 18, 2025
About Us
About Us

Provide a constantly updating feed of the latest security news and developments specific to Indonesia.

Facebook X (Twitter) Pinterest YouTube WhatsApp
Our Picks

Safe Coding Vibe: Full New Guide

June 19, 2025

Bluenoroff Deepfake Zoom AFM Hits Crypto employee with malicious MacOS software

June 19, 2025

Discover the areas hiding in trusted instruments – find out how in this free expert session

June 19, 2025
Most Popular

In Indonesia, crippling immigration ransomware breach sparks privacy crisis

July 6, 2024

Why Indonesia’s Data Breach Crisis Calls for Better Security

July 6, 2024

Indonesia’s plan to integrate 27,000 govt apps in one platform welcomed but data security concerns linger

July 6, 2024
© 2025 indoguardonline.com
  • Home
  • About us
  • Contact us
  • Privacy Policy

Type above and press Enter to search. Press Esc to cancel.