Tag: Authentication Bypass

Palo Alto Networks Patches Authentication Bypass Exploit in PAN-OS Software
News

Palo Alto Networks Patches Authentication Bypass Exploit in PAN-OS Software

A high-severity security vulnerability in Palo Alto Networks' PAN-OS software that might lead to an authentication bypass has been fixed. The vulnerability has a CVSS score of 7.8 out of 10.0 and is tagged as CVE-2025-0108. However, limiting access to the administrative interface to a jump box lowers the score to 5.1. An unauthenticated attacker with network access to the management web interface can circumvent the authentication that the PAN-OS management web interface would otherwise require and launch specific PHP scripts thanks to an authentication bypass in the Palo Alto Networks PAN-OS software, the company stated in an advisory read more about Palo Alto Networks Patches Authentication Bypass Exploit in PAN-OS Software. Get up to date on the latest cybersecurity news&n...
ASUS Patches Critical Authentication Bypass Flaw in Multiple Router Models
News

ASUS Patches Critical Authentication Bypass Flaw in Multiple Router Models

Software patches have been released by ASUS to fix a serious security vulnerability that was affecting its routers and could be used by hostile actors to get beyond authentication. The vulnerability, identified as CVE-2024-3080, has a CVSS score of 9.8 out of a possible 10.0. According to a description of the vulnerability provided by the Taiwan Computer Emergency Response Team / Coordination Center (TWCERT/CC), some ASUS router models have an authentication bypass vulnerability that makes it possible for unauthenticated remote attackers to log in to the device. The Taiwanese company also addressed a high-severity buffer overflow vulnerability known as CVE-2024-3079 (CVSS score: 7.2), which may be used as a weapon by remote attackers with administrative rights to take control of ...