$4.99/mo - Save 61% With Exclusive 2-Year Plan + 4 Months Free!Claim Now

Critical Flaws in Palo Alto Tools Spark Active Exploits

  • Last updated November 18, 2024
  • written by
    Writer

Washington, D.C., November 15, 2024Critical flaws in Palo Alto Networks’ tools are actively exploited, risking sensitive data exposure and firewall security. CISA demands urgent patching.

The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has issued an urgent alert regarding two critical vulnerabilities in Palo Alto Networks’ Expedition tool. These flaws, actively exploited by attackers, threaten sensitive data security and firewall integrity nationwide.

CISA mandates federal agencies to patch these vulnerabilities by December 5, 2024, to prevent further exploitation. Identified as CVE-2024-9463 (OS Command Injection) and CVE-2024-9465 (SQL Injection), these vulnerabilities allow attackers to execute arbitrary OS commands and access sensitive database contents.

This puts usernames, passwords, API keys, and device configurations at severe risk. A third flaw, with a CVSS score of 9.3, involves a remote command execution vulnerability targeting exposed firewall management interfaces.

These vulnerabilities impact several U.S. states where federal infrastructure relies on Expedition’s migration tools for seamless security updates. CISA’s Known Exploited Vulnerabilities (KEV) catalog lists them as priority threats, urging public and private entities to act swiftly.

Security experts warn this could evolve into a broader attack. Palo Alto Networks has assured a comprehensive fix, advising all organizations to secure exposed systems immediately.


Other News At VPNRanks


Hey, wait!

Stay informed on the latest privacy updates, cybersecurity insights, and internet freedom news by following VPNRanks news daily! As your primary resource for critical updates in online security, we ensure you’re always in the know. Make VPNRanks your go-to guide for safeguarding your digital life!