216.73.217.22

Threat Brief: Operation Lunar Peek, Activity Related to CVE-2024-0012

· Published 18/11/2024 19:19 · Modified 19/11/2024 09:34

Export JSON

Essential information

Published
18/11/2024 19:19
Modified
19/11/2024 09:34
Tags
2024-11-18 CVE-2024-0012 CVE-2024-9474 authentication bypass pan-os privilege-escalation vpn webshell
Related entities
8 techniques (mitre)

Description

A critical vulnerability () in Palo Alto Networks software allows unauthenticated attackers to gain administrator privileges on affected devices. The issue affects versions 10.2, 11.0, 11.1, and 11.2, but not Cloud NGFW or Prisma Access. Limited exploitation attempts have been observed, primarily from anonymous services. Post-exploitation activities include command execution and deployment. Palo Alto Networks is actively monitoring the situation, dubbed Operation Lunar Peek, and has released patches. Customers are urged to update their systems and restrict management interface access to trusted internal IP addresses to mitigate the risk.

External references