Tuesday, 21 Apr 2026
Subscribe
logo
  • Global
  • AI
  • Cloud Computing
  • Edge Computing
  • Security
  • Investment
  • Sustainability
  • More
    • Colocation
    • Quantum Computing
    • Regulation & Policy
    • Infrastructure
    • Power & Cooling
    • Design
    • Innovations
    • Blog
Font ResizerAa
Data Center NewsData Center News
Search
  • Global
  • AI
  • Cloud Computing
  • Edge Computing
  • Security
  • Investment
  • Sustainability
  • More
    • Colocation
    • Quantum Computing
    • Regulation & Policy
    • Infrastructure
    • Power & Cooling
    • Design
    • Innovations
    • Blog
Have an existing account? Sign In
Follow US
© 2022 Foxiz News Network. Ruby Design Company. All Rights Reserved.
Data Center News > Blog > Global Market > Palo Alto Networks firewall bug being exploited by threat actors: Report
Global Market

Palo Alto Networks firewall bug being exploited by threat actors: Report

Last updated: February 15, 2025 3:47 am
Published February 15, 2025
Share
Attention, warning sign; exclamation mark under a magnifying glass.
SHARE

The difficulty doesn’t have an effect on the corporate’s Cloud NGFW or Prisma Entry software program.

Greynoise said exploitation began around Tuesday of this week. Assetnote published research concerning the gap on Wednesday. Palo Alto Networks printed its advisory the identical day.

‘Bizarre path-processing habits’

The vulnerability, Assetnote stated, is a “bizarre path-processing habits” within the Apache HTTP server a part of PAN-OS, which, together with Nginx, handles net requests to entry the PAN-OS administration interface. The net request first hits the Nginx reverse proxy, and whether it is on a port that signifies it’s destined for the administration interface, PAN-OS units a number of headers; a very powerful of them is X-pan AuthCheck. The Nginx configuration then goes by way of a number of location checks and selectively units the auth test to off. The request is then proxied to Apache, which is able to re-normalize and re-process the request in addition to apply a rewrite rule below sure situations. If the file requested is a PHP file, Apache will then move by way of the request by way of mod_php FCGI, which enforces authentication primarily based upon the header.

The issue is that Apache could course of the trail or headers in a different way to Nginx earlier than the entry request is handed to PHP, so if there’s a distinction between what Nginx thinks a request appears like and what Apache thinks it appears like, an attacker might obtain an authentication bypass. 

Assetnote describes this as a “fairly frequent” structure downside the place authentication is enforced at a proxy layer, however then the request is handed by way of a second layer with completely different habits. “Basically,” the analysis observe added, “these architectures result in header smuggling and path confusion, which may end up in many impactful bugs.”

See also  Broadcom changes VMware pricing amid customer backlash and EU questioning

Source link

TAGGED: actors, Alto, Bug, exploited, Firewall, Networks, Palo, report, Threat
Share This Article
Twitter Email Copy Link Print
Previous Article Antithesis Antithesis Raises $30M in Funding
Next Article New smart jacket uses AI to prevent overheating and discomfort New smart jacket uses AI to prevent overheating and discomfort
Leave a comment

Leave a Reply Cancel reply

Your email address will not be published. Required fields are marked *

Your Trusted Source for Accurate and Timely Updates!

Our commitment to accuracy, impartiality, and delivering breaking news as it happens has earned us the trust of a vast audience. Stay ahead with real-time updates on the latest events, trends.
FacebookLike
TwitterFollow
InstagramFollow
YoutubeSubscribe
LinkedInFollow
MediumFollow
- Advertisement -
Ad image

Popular Posts

HPE’s latest Juniper routers target large‑scale AI fabrics

The three new fashions give clients a number of choices for configurations and throughput capability,…

March 1, 2026

Understanding the Intersection of Observability and Zero Trust

At RSAC24, Gigamon CISO Chaim Mazal shared his ideas on zero belief and why it…

May 31, 2024

Yescoin’s Web3 Expansion Continues with $2.4M Prize Pool and Public Sale on Yescoin Foundation

Kingstown, Saint Vincent and the Grenadines, March tenth, 2025, Chainwire Revolutionizing Consumer Engagement and Token…

March 10, 2025

Spectro Cloud arms AI Infrastructure with NVIDIA stack for telco and edge scale-up

Spectro Cloud introduced the mixing of its Palette platform with NVIDIA DOCA 3.0 and NVIDIA…

June 18, 2025

How Microsoft and Serverfarm Are Shaping Sustainable Data Centers

/*! elementor - v3.22.0 - 26-06-2024 */ .elementor-heading-title{padding:0;margin:0;line-height:1}.elementor-widget-heading .elementor-heading-title>a{shade:inherit;font-size:inherit;line-height:inherit}.elementor-widget-heading .elementor-heading-title.elementor-size-small{font-size:15px}.elementor-widget-heading .elementor-heading-title.elementor-size-medium{font-size:19px}.elementor-widget-heading .elementor-heading-title.elementor-size-large{font-size:29px}.elementor-widget-heading .elementor-heading-title.elementor-size-xl{font-size:39px}.elementor-widget-heading .elementor-heading-title.elementor-size-xxl{font-size:59px}How Microsoft…

August 23, 2024

You Might Also Like

One in five UK firms move AI workloads overseas due to high energy costs
Global Market

One in five UK firms move AI workloads overseas due to high energy costs

By saad
Wireless router generic image
Global Market

AI fuels wireless talent shortage

By saad
AI agent consuming and using enterprise data in retail-as-a-service application.
Global Market

Cloudflare wants to rebuild the network for the age of AI agents

By saad
Why physical security needs a bigger role
Global Market

Why physical security needs a bigger role

By saad
Data Center News
Facebook Twitter Youtube Instagram Linkedin

About US

Data Center News: Stay informed on the pulse of data centers. Latest updates, tech trends, and industry insights—all in one place. Elevate your data infrastructure knowledge.

Top Categories
  • Global Market
  • Infrastructure
  • Innovations
  • Investments
Usefull Links
  • Home
  • Contact
  • Privacy Policy
  • Terms & Conditions

© 2024 – datacenternews.tech – All rights reserved

Welcome Back!

Sign in to your account

Lost your password?
We use cookies to ensure that we give you the best experience on our website. If you continue to use this site we will assume that you are happy with it.
You can revoke your consent any time using the Revoke consent button.