Close Menu
Indo Guard OnlineIndo Guard Online
  • Home
  • Cyber Security
  • Risk Management
  • Travel
  • Security News
  • Tech
  • More
    • Data Privacy
    • Data Protection
    • Global Security
What's Hot

FBI warns about expanded spider attacks on airline using social engineering

June 28, 2025

The new AI Facebook tool asks for upload your photos for plot ideas, causing privacy trouble

June 28, 2025

From the theft of the browser to the intelligence collection instrument

June 28, 2025
Facebook X (Twitter) Instagram
Facebook X (Twitter) Instagram YouTube
Indo Guard OnlineIndo Guard Online
Subscribe
  • Home
  • Cyber Security
  • Risk Management
  • Travel
  • Security News
  • Tech
  • More
    • Data Privacy
    • Data Protection
    • Global Security
Indo Guard OnlineIndo Guard Online
Home » CISA notes two heavily exploited Palo Alto deficiencies; New RCE attack confirmed
Global Security

CISA notes two heavily exploited Palo Alto deficiencies; New RCE attack confirmed

AdminBy AdminNovember 15, 2024No Comments2 Mins Read
Palo Alto Network Flaws
Share
Facebook Twitter LinkedIn Pinterest Email Copy Link


November 15, 2024Ravi LakshmananNetwork Security / Vulnerability

Disadvantages of the Palo Alto network

The US Cybersecurity and Infrastructure Security Agency (CISA) warned on Thursday that two more flaws affecting Palo Alto Networks Expedition have been actively exploited in the wild.

Before that there is added vulnerabilities of its known vulnerabilities used (KEV) directory that requires Federal Civilian Executive Branch (FCEB) agencies to apply required updates by December 5, 2024.

Cyber ​​security

The security flaws are listed below –

  • CVE-2024-9463 (CVSS Score: 9.9) – Palo Alto Networks Expedition OS command implementation vulnerability
  • CVE-2024-9465 (CVSS Score: 9.3) – SQL injection vulnerability in Palo Alto Networks Expedition

Successful exploitation of the vulnerabilities could allow an unauthenticated attacker to execute arbitrary OS commands as root in the Expedition migration tool or to expose the contents of its database.

This can then open the way to reveal usernames, plaintext passwords, device configurations, and device API keys of PAN-OS firewalls, or to create and read arbitrary files on a vulnerable system.

Palo Alto Networks addressed these flaws in the security updates released on October 9, 2024. Since then the company revised its original recommendation to acknowledge that it was “aware of reports from CISA that there was evidence of active use of CVE-2024-9463 and CVE-2024-9465.”

However, not much is known about how these vulnerabilities are exploited, by whom, and how widespread these attacks are.

The development also came a week after CISA was notified active exploitation of CVE-2024-5910 (CVSS score: 9.3), another critical flaw affecting Expedition.

Palo Alto Networks confirms that the new flaw is under limited attack

Cyber ​​security

Since then, so has Palo Alto Networks confirmed that it discovered an unauthenticated remote command execution vulnerability used against a small subset of firewall management interfaces exposed to the Internet, urging customers to protect them.

“Palo Alto Networks has observed a threat exploiting an unauthenticated remote command execution vulnerability against a limited number of firewall management interfaces exposed to the Internet,” it said. added.

The company, which investigates the malicious activity and assigned the vulnerability a CVSS score of 9.3 (without a CVE identifier), also said it is “preparing to release fixes and threat prevention signatures as soon as possible.”

Did you find this article interesting? Follow us Twitter  and LinkedIn to read more exclusive content we publish.





Source link

Share. Facebook Twitter Pinterest LinkedIn Tumblr Email Copy Link
Admin
  • Website

Related Posts

FBI warns about expanded spider attacks on airline using social engineering

June 28, 2025

The new AI Facebook tool asks for upload your photos for plot ideas, causing privacy trouble

June 28, 2025

From the theft of the browser to the intelligence collection instrument

June 28, 2025

More than 1000 SOHO devices hacked in China associated with cyber-science associated with cyber

June 27, 2025

Posted and Pubshell Sarsware used in Tibet’s Mustang Panda attack

June 27, 2025

The Chinese Silver Fox Group uses fake web -sats to deliver Sainbox Rat and Hidden Rortkit

June 27, 2025
Add A Comment
Leave A Reply Cancel Reply

Loading poll ...
Coming Soon
Do You Like Our Website
: {{ tsp_total }}

Subscribe to Updates

Get the latest security news from Indoguardonline.com

Latest Posts

FBI warns about expanded spider attacks on airline using social engineering

June 28, 2025

The new AI Facebook tool asks for upload your photos for plot ideas, causing privacy trouble

June 28, 2025

From the theft of the browser to the intelligence collection instrument

June 28, 2025

More than 1000 SOHO devices hacked in China associated with cyber-science associated with cyber

June 27, 2025

Posted and Pubshell Sarsware used in Tibet’s Mustang Panda attack

June 27, 2025

The Chinese Silver Fox Group uses fake web -sats to deliver Sainbox Rat and Hidden Rortkit

June 27, 2025

Business -SUCKS FOR AGENTIC AI SOC -Analytics

June 27, 2025

Transfer of person transfer is increased by threats when directed by scanning and disadvantages CVE

June 27, 2025
About Us
About Us

Provide a constantly updating feed of the latest security news and developments specific to Indonesia.

Facebook X (Twitter) Pinterest YouTube WhatsApp
Our Picks

FBI warns about expanded spider attacks on airline using social engineering

June 28, 2025

The new AI Facebook tool asks for upload your photos for plot ideas, causing privacy trouble

June 28, 2025

From the theft of the browser to the intelligence collection instrument

June 28, 2025
Most Popular

In Indonesia, crippling immigration ransomware breach sparks privacy crisis

July 6, 2024

Why Indonesia’s Data Breach Crisis Calls for Better Security

July 6, 2024

Indonesia’s plan to integrate 27,000 govt apps in one platform welcomed but data security concerns linger

July 6, 2024
© 2025 indoguardonline.com
  • Home
  • About us
  • Contact us
  • Privacy Policy

Type above and press Enter to search. Press Esc to cancel.