Palo Alto Networks says it fixed two major firewall zero-days being used in thousands of attacks




  • Palo Alto Networks releases patch for two serious flaws impacting its firewalls
  • The flaws were being abused in the wild to drop malware
  • CISA added them to its KEV catalog

Palo Alto Networks has revealed it fixed two major vulnerabilities plaguing its firewalls.

The bugs are an authentication bypass in the PAN-OS management web interface (CVE-2024-0012), and a privilege escalation flaw in PAN-OS (CVE-2024-9474). The former has a severity score of 9.3 (critical), and grants crooks the ability to gain admin privileges on the target endpoint, and the latter has a lower score, 6.9 (medium), but helps run commands on the firewall.



Source link

Leave a Reply

Your email address will not be published. Required fields are marked *