Cybersecurity
– Deagreez/Getty Images

Palo Alto Networks recently reported and patched a critical vulnerability in the GlobalProtect feature of its PAN-OS software. However, as of yesterday, data from the Shadowserver Foundation indicated that approximately 5,373 GlobalProtect instances remained vulnerable.

Meanwhile, Siemens has issued an advisory stating that its industrial product -- Ruggedcom Application Processing Engine (APE) 1808 - is affected by this vulnerability. The product is Siemens’ industrial application hosting platform, designed to serve as a substation edge computing platform to run substation automation software, data concentration, station-level automation and protocol conversion functions, according to the company.

Siemens advises customers to disable the GlobalProtect gateway and GlobalProtect portal and implement the workarounds and mitigation provided by Palo Alto Networks.

What you need to know about the critical bug

The vulnerability (CVE-2024-3400) has the highest severity score of 10.0 on the Common Vulnerability Scoring System (CVSS) and is marked as the highest urgency in Palo Alto Networks’ advisory.

The issue was first discovered on April 10 by researchers at security firm Volexity, who received alerts regarding suspect network traffic emanating from a customer’s Palo Alto Networks firewall. Two days later, Palo Alto Networks sent out a security advisory.

“A critical command injection vulnerability in Palo Alto Networks PAN-OS software enables an unauthenticated attacker to execute arbitrary code with root privileges on the firewall,” Palo Alto Networks Unit 42 wrote in a threat brief.

The vulnerability affects firewalls with PAN-OS versions 10.2, 11.0, and 11.1 when configured with the GlobalProtect gateway or GlobalProtect portal or both. Palo Alto Networks' cloud firewalls, (Cloud next-generation firewall (NGFX)), Panorama appliances or Prisma Access products are not affected by this issue.

Palo Alto Networks is tracking the initial exploitation of this vulnerability under the name Operation MidnightEclipse and is aware of “an increasing number of attacks that leverage the exploitation of this vulnerability.”

“It is important to note that the vast majority of cases that Unit 42 has responded to have been unsuccessful attempts to exploit the vulnerability and some compromises of PAN-OS that are limited to confirming that the device is exploitable. Other cases have included limited attempts in which a file on the hard drive has been copied to a location accessible via a web request and a very limited number of compromises that led to interactive command execution,” Unit 42 wrote.

In addition, Shadowserver Foundation, a nonprofit security organization that gathers and analyzes data on malicious Internet activity, tweeted that 22, 542 possibly vulnerable Intrusion Prevention System (IPS) were found on April 18 associated with the vulnerability.

Mitigation for the Palo Alto Networks firewall vulnerability

Palo Alto Networks recommends customers with a Threat Prevention subscription block attacks for this vulnerability using Threat IDs 95187, 95189, and 95191.

Additionally, the vendor urges customers to immediately upgrade to a fixed version of PAN-OS to protect their devices.

In an earlier version of Palo Alto Networks’ security advisory, the company listed disabling device telemetry as a secondary mitigation action. But in its updated version, it noted this vulnerability does not require device telemetry to be enabled for PAN-OS firewalls to be exposed to attacks related to this vulnerability.