Palo Alto GlobalProtect Authentication Bypass Under Active Attack

CVE-2024-0257 enables attackers to bypass VPN authentication using forged cookies, with exploitation confirmed across multiple environments.

AI-generated illustration depicting vulnerability for the story: Palo Alto GlobalProtect Authentication Bypass Under Active Attack

CVE-2024-0257 enables attackers to bypass VPN authentication using forged cookies, with exploitation confirmed across multiple environments.

Summary

  • Palo Alto’s CVE-2024-0257 allows attackers to bypass GlobalProtect VPN authentication through forged override cookies
  • Active exploitation confirmed since at least May 17 across multiple customer environments
  • Vulnerability stems from improper cookie validation when same certificate is used for HTTPS and authentication
  • CISA has added the flaw to its KEV catalog with June 1 deadline for federal agencies

Vulnerability Details

CVE-2024-0257 affects PAN-OS deployments using GlobalProtect authentication override cookies under specific configurations. The vulnerability allows attackers to craft their own authentication cookies that the firewall accepts as legitimate. The risk is highest where organizations use the same certificate for both HTTPS services and authentication override cookies, providing attackers with the information needed to generate convincing forgeries.

Active Exploitation Confirmed

Initially disclosed on May 13 with a medium-severity rating, Palo Alto has now elevated the severity and applied its highest urgency label. Rapid7 researchers observed successful exploitation across multiple customer environments dating back to at least May 17. In confirmed attacks, cybercriminals established unauthorized VPN sessions on vulnerable systems, potentially granting access to internal corporate networks without legitimate credentials.

Attack Impact and Scope

Rapid7 documented multiple waves of activity targeting vulnerable devices. In some cases, attackers successfully obtained VPN IP addresses and network access. However, the security firm reported no evidence of successful lateral movement following initial access in the incidents it investigated. The vulnerability has now been added to CISA’s Known Exploited Vulnerabilities catalog, with federal agencies required to patch or secure affected systems by June 1.

Recent Pattern of Palo Alto Vulnerabilities

This incident follows another recent Palo Alto emergency less than a month earlier. In May, state-backed attackers exploited CVE-2024-0300, a critical remote code execution flaw in the PAN-OS User-ID Authentication Portal, before patches became widely available. The company updated its advisory stating it has become aware of limited exploit attempts on unpatched PAN-OS devices without mitigations applied.

Why it matters

This vulnerability represents a fundamental authentication bypass that grants attackers direct VPN access to internal networks. With confirmed active exploitation and the involvement of multiple threat actors, unpatched GlobalProtect gateways present immediate risk of network compromise. The timing compounds concerns given recent patterns of Palo Alto vulnerabilities being exploited before widespread patching.

What to do now

  • Apply available patches for supported PAN-OS releases immediately
  • Review certificate configurations to ensure separate certificates are used for HTTPS services and authentication override cookies
  • Monitor VPN access logs for unauthorized sessions or suspicious authentication patterns
  • Implement additional network segmentation controls to limit potential lateral movement from VPN access points

Sources