CISA warns of critical Palo Alto Networks bug exploited in attacks
ID: 70b62e15-8db6-55da-96c5-223eb84fb89f
STIX ID: report--70b62e15-8db6-55da-96c5-223eb84fb89f
Feed Name: Bleeping Computer
Threat Score
CISA warns that attackers are exploiting a critical missing-authentication vulnerability (CVE-2024-5910) in Palo Alto Networks Expedition, which can allow remote admin account takeover and access to secrets; a proof-of-concept and chaining with a command-injection flaw (CVE-2024-9464) enable unauthenticated arbitrary command execution and potential PAN-OS firewall takeover, prompting patches, mitigation guidance, and inclusion in CISA's Known Exploited Vulnerabilities catalog.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
