Skip to main content
عربي
logo

NCSC-TAD-2411-001

Severity Level: Critical
Vulnerability

Reference No.: NCSC-TAD-2411-001CVSS 0

Critical Vulnerabilities in Palo Alto Networks and Fortinet

Threat Type:
N/A
TLP:
CLEAR
CVE:
CVE-2024-0012, CVE-2024-9474, CVE-2024-47575

Overview

Palo Alto Networks has released security patches addressing two critical vulnerabilities, CVE-2024-0012 and CVE-2024-9474, affecting multiple Palo Alto Network products.

The first vulnerability (CVE-2024-9474: Medium) exists in the PAN-OS web management interface and could allow a PAN-OS administrator with access to the interface to escalate their privileges to root. Successful exploitation of this vulnerability could allow an attacker to gain full control over a Palo Alto Networks firewall, potentially leading to data theft, unauthorized access to sensitive information, and disruption of network services.

The second vulnerability (CVE-2024-0012: Critical) exists in the PAN-OS web management interface and could allow an unauthenticated attacker with network access to the interface to gain PAN-OS administrator privileges. Successful exploitation of this vulnerability could allow an attacker to gain complete control over a Palo Alto Networks firewall, potentially leading to data theft, unauthorized access to sensitive information, and disruption of network services. The company recommends securing access to the management interface and avoiding exposing it to the Internet.

Fortinet has released security patches addressing a critical vulnerability. CVE-2024- 47575, affecting Fortinet devices. This vulnerability could allow a remote, unauthenticated attacker to execute arbitrary code on vulnerable devices. Successful exploitation could lead to complete system compromise, including data theft, unauthorized access, and potential disruption of network services.

Affected Technologies

  • PAN-OS
  • FortiManager

Mitigation and Immediate Actions

  1. 01

    Palo Alto Networks: Upgrade to a fixed version.

  2. 02

    Palo Alto Networks: Restrict access to the management interface.

  3. 03

    Fortinet: Upgrade to a fixed version.

  4. 04

    Fortinet: Avoid exposing FortiManager to the public internet.

  5. 05

    Fortinet: Configure Fortinet logs for monitoring.

References