Saturday, 21 Mar 2026
Subscribe
logo
  • Global
  • AI
  • Cloud Computing
  • Edge Computing
  • Security
  • Investment
  • Sustainability
  • More
    • Colocation
    • Quantum Computing
    • Regulation & Policy
    • Infrastructure
    • Power & Cooling
    • Design
    • Innovations
    • Blog
Font ResizerAa
Data Center NewsData Center News
Search
  • Global
  • AI
  • Cloud Computing
  • Edge Computing
  • Security
  • Investment
  • Sustainability
  • More
    • Colocation
    • Quantum Computing
    • Regulation & Policy
    • Infrastructure
    • Power & Cooling
    • Design
    • Innovations
    • Blog
Have an existing account? Sign In
Follow US
© 2022 Foxiz News Network. Ruby Design Company. All Rights Reserved.
Data Center News > Blog > Global Market > Palo Alto Networks firewall bug being exploited by threat actors: Report
Global Market

Palo Alto Networks firewall bug being exploited by threat actors: Report

Last updated: February 15, 2025 3:47 am
Published February 15, 2025
Share
Attention, warning sign; exclamation mark under a magnifying glass.
SHARE

The difficulty doesn’t have an effect on the corporate’s Cloud NGFW or Prisma Entry software program.

Greynoise said exploitation began around Tuesday of this week. Assetnote published research concerning the gap on Wednesday. Palo Alto Networks printed its advisory the identical day.

‘Bizarre path-processing habits’

The vulnerability, Assetnote stated, is a “bizarre path-processing habits” within the Apache HTTP server a part of PAN-OS, which, together with Nginx, handles net requests to entry the PAN-OS administration interface. The net request first hits the Nginx reverse proxy, and whether it is on a port that signifies it’s destined for the administration interface, PAN-OS units a number of headers; a very powerful of them is X-pan AuthCheck. The Nginx configuration then goes by way of a number of location checks and selectively units the auth test to off. The request is then proxied to Apache, which is able to re-normalize and re-process the request in addition to apply a rewrite rule below sure situations. If the file requested is a PHP file, Apache will then move by way of the request by way of mod_php FCGI, which enforces authentication primarily based upon the header.

The issue is that Apache could course of the trail or headers in a different way to Nginx earlier than the entry request is handed to PHP, so if there’s a distinction between what Nginx thinks a request appears like and what Apache thinks it appears like, an attacker might obtain an authentication bypass. 

Assetnote describes this as a “fairly frequent” structure downside the place authentication is enforced at a proxy layer, however then the request is handed by way of a second layer with completely different habits. “Basically,” the analysis observe added, “these architectures result in header smuggling and path confusion, which may end up in many impactful bugs.”

See also  Arista rides AI wave, but battle for campus networks looms

Source link

TAGGED: actors, Alto, Bug, exploited, Firewall, Networks, Palo, report, Threat
Share This Article
Twitter Email Copy Link Print
Previous Article Antithesis Antithesis Raises $30M in Funding
Next Article New smart jacket uses AI to prevent overheating and discomfort New smart jacket uses AI to prevent overheating and discomfort
Leave a comment

Leave a Reply Cancel reply

Your email address will not be published. Required fields are marked *

Your Trusted Source for Accurate and Timely Updates!

Our commitment to accuracy, impartiality, and delivering breaking news as it happens has earned us the trust of a vast audience. Stay ahead with real-time updates on the latest events, trends.
FacebookLike
TwitterFollow
InstagramFollow
YoutubeSubscribe
LinkedInFollow
MediumFollow
- Advertisement -
Ad image

Popular Posts

Alternative Payments Raises $22M in Total Funding

Alternative Payments, a NYC-based B2B funds and checkout infrastructure supplier, raised $22M in funding. The…

April 28, 2025

How data centre network infrastructure is evolving to deliver on AI’s promises

Jürgen Hatheier, Worldwide CTO at Ciena, explains why the surge in AI coaching will eclipse…

May 25, 2025

Hitachi Wields Industrial Know-How to Compete in the Physical AI Race

Bodily AI – the department of synthetic intelligence that controls robots and industrial equipment in…

February 23, 2026

Biden to Push Geothermal Energy to Boost AI Growth

(Bloomberg) -- President Joe Biden’s administration plans to streamline allowing for geothermal power growth as…

January 8, 2025

CapeZero Raises $2.6M in Seed Funding

CapeZero, a NYC-based supplier of a software program platform that streamlines monetary workflow for clear…

January 24, 2025

You Might Also Like

data center men servers cloud
Global Market

IDC: Dell leads server market driven by AI infrastructure needs

By saad
Achieving success with the cloud continuum
Global Market

Democratising cloud skills could be Europe’s next competitive edge

By saad
Nvidia GTC 2026 Vera Rubin
Global Market

Nvidia overhauls the data center for OpenClaw era

By saad
Antin Infrastructure Partners completes takeover of NorthC
Global Market

Antin Infrastructure Partners completes takeover of NorthC

By saad
Data Center News
Facebook Twitter Youtube Instagram Linkedin

About US

Data Center News: Stay informed on the pulse of data centers. Latest updates, tech trends, and industry insights—all in one place. Elevate your data infrastructure knowledge.

Top Categories
  • Global Market
  • Infrastructure
  • Innovations
  • Investments
Usefull Links
  • Home
  • Contact
  • Privacy Policy
  • Terms & Conditions

© 2024 – datacenternews.tech – All rights reserved

Welcome Back!

Sign in to your account

Lost your password?
We use cookies to ensure that we give you the best experience on our website. If you continue to use this site we will assume that you are happy with it.
You can revoke your consent any time using the Revoke consent button.