HomeVulnerabilityHackers acquire root entry to Palo Alto firewalls by means of chained...

Hackers acquire root entry to Palo Alto firewalls by means of chained bugs

Discovery of CVE-2025-0108 got here from post-patch evaluation of CVE-2024-9474, a medium-severity flaw (CVSS 6.9/10) that was actively exploited in November. At the moment, attackers have been seen chaining CVE-2024-9474 with one other vital authentication bypass vulnerability (CVE-2024-0012) affecting PAN-OS, and collectively they allowed executing codes remotely on compromised methods.

Now risk actors are chaining CVE-2025-0108, and CVE-2024-9474 with a high-severity flaw (CVE-2025-0111) for unauthorized root-level entry to susceptible methods, probably permitting extraction of delicate configuration knowledge and consumer credentials.

All three vulnerabilities have an effect on PAN-OS variations 10.1, 10.2, 11.1, and 11.2, and have obtained patches respectively. Palo Alto Networks confirmed that its Cloud NGFW and Prisma Entry providers should not impacted.

See also  Crowdstrike cybersecurity report highlights a spike in bodily assaults on privileged customers
- Advertisment -spot_img
RELATED ARTICLES

LEAVE A REPLY

Please enter your comment!
Please enter your name here

- Advertisment -

Most Popular