Saturday, 13 Dec 2025
Subscribe
logo
  • Global
  • AI
  • Cloud Computing
  • Edge Computing
  • Security
  • Investment
  • Sustainability
  • More
    • Colocation
    • Quantum Computing
    • Regulation & Policy
    • Infrastructure
    • Power & Cooling
    • Design
    • Innovations
    • Blog
Font ResizerAa
Data Center NewsData Center News
Search
  • Global
  • AI
  • Cloud Computing
  • Edge Computing
  • Security
  • Investment
  • Sustainability
  • More
    • Colocation
    • Quantum Computing
    • Regulation & Policy
    • Infrastructure
    • Power & Cooling
    • Design
    • Innovations
    • Blog
Have an existing account? Sign In
Follow US
© 2022 Foxiz News Network. Ruby Design Company. All Rights Reserved.
Data Center News > Blog > Global Market > Palo Alto Networks firewall bug being exploited by threat actors: Report
Global Market

Palo Alto Networks firewall bug being exploited by threat actors: Report

Last updated: February 15, 2025 3:47 am
Published February 15, 2025
Share
Attention, warning sign; exclamation mark under a magnifying glass.
SHARE

The difficulty doesn’t have an effect on the corporate’s Cloud NGFW or Prisma Entry software program.

Greynoise said exploitation began around Tuesday of this week. Assetnote published research concerning the gap on Wednesday. Palo Alto Networks printed its advisory the identical day.

‘Bizarre path-processing habits’

The vulnerability, Assetnote stated, is a “bizarre path-processing habits” within the Apache HTTP server a part of PAN-OS, which, together with Nginx, handles net requests to entry the PAN-OS administration interface. The net request first hits the Nginx reverse proxy, and whether it is on a port that signifies it’s destined for the administration interface, PAN-OS units a number of headers; a very powerful of them is X-pan AuthCheck. The Nginx configuration then goes by way of a number of location checks and selectively units the auth test to off. The request is then proxied to Apache, which is able to re-normalize and re-process the request in addition to apply a rewrite rule below sure situations. If the file requested is a PHP file, Apache will then move by way of the request by way of mod_php FCGI, which enforces authentication primarily based upon the header.

The issue is that Apache could course of the trail or headers in a different way to Nginx earlier than the entry request is handed to PHP, so if there’s a distinction between what Nginx thinks a request appears like and what Apache thinks it appears like, an attacker might obtain an authentication bypass. 

Assetnote describes this as a “fairly frequent” structure downside the place authentication is enforced at a proxy layer, however then the request is handed by way of a second layer with completely different habits. “Basically,” the analysis observe added, “these architectures result in header smuggling and path confusion, which may end up in many impactful bugs.”

See also  Microsoft could have prevented Chinese cloud email hack, US cyber report says

Source link

TAGGED: actors, Alto, Bug, exploited, Firewall, Networks, Palo, report, Threat
Share This Article
Twitter Email Copy Link Print
Previous Article Antithesis Antithesis Raises $30M in Funding
Next Article New smart jacket uses AI to prevent overheating and discomfort New smart jacket uses AI to prevent overheating and discomfort
Leave a comment

Leave a Reply Cancel reply

Your email address will not be published. Required fields are marked *

Your Trusted Source for Accurate and Timely Updates!

Our commitment to accuracy, impartiality, and delivering breaking news as it happens has earned us the trust of a vast audience. Stay ahead with real-time updates on the latest events, trends.
FacebookLike
TwitterFollow
InstagramFollow
YoutubeSubscribe
LinkedInFollow
MediumFollow
- Advertisement -
Ad image

Popular Posts

UK Data Center Event Addresses Industry’s Biggest Challenges | DCN

Knowledge Centre World UK opened its doorways in London right this moment, welcoming delegates from…

March 6, 2024

Turkey Data Center Market Poised for Growth with USD 688 Million Forecast by 2029

DUBLIN–(BUSINESS WIRE)–The “Turkey Data Center Market – Investment Analysis & Growth Opportunities 2024-2029” report has…

July 4, 2024

Meta Plans Nearly $1B Data Center Project in Wisconsin – Report

(Bloomberg) -- Meta Platforms plans to spend practically $1 billion on the event of a…

April 7, 2025

GovWell Raises $4.5M in Seed Funding

GovWell, a New York-based supplier of a govtech software program platform, raised $4.5m in seed…

August 3, 2024

Biden Tightens Chip Controls on China as Clock Ticks Down

The Biden administration introduced Monday a long-anticipated spherical of restrictions on exports of semiconductor chips…

December 3, 2024

You Might Also Like

Data center / enterprise networking
Global Market

P4 programming: Redefining what’s possible in network infrastructure

By saad
Why data centre megadeals must prove their value
Global Market

Why data centre megadeals must prove their value

By saad
photo illustration of clouds in the shape of dollar signs above a city
Global Market

Cloud providers continue to push EU court to undo Broadcom-VMware merger

By saad
Kao SEED Fund awards £30,000 to Harlow community projects
Global Market

Kao SEED Fund awards £30,000 to Harlow community projects

By saad
Data Center News
Facebook Twitter Youtube Instagram Linkedin

About US

Data Center News: Stay informed on the pulse of data centers. Latest updates, tech trends, and industry insights—all in one place. Elevate your data infrastructure knowledge.

Top Categories
  • Global Market
  • Infrastructure
  • Innovations
  • Investments
Usefull Links
  • Home
  • Contact
  • Privacy Policy
  • Terms & Conditions

© 2024 – datacenternews.tech – All rights reserved

Welcome Back!

Sign in to your account

Lost your password?
We use cookies to ensure that we give you the best experience on our website. If you continue to use this site we will assume that you are happy with it.
You can revoke your consent any time using the Revoke consent button.