Quick Facts
- Attackers chained CVE-2024-0012 and CVE-2024-9474 to gain root access to more than 13,000 Palo Alto Networks firewall management interfaces
- CVSS scored the vulnerabilities at 9.3 and 6.9, with the lower score falling below many enterprise patch thresholds
- The attack exposed critical flaws in vulnerability scoring systems that fail to account for chained exploits
Attackers gained root access to more than 13,000 Palo Alto Networks firewall devices by chaining two vulnerabilities that appeared manageable when scored separately.
During Operation Lunar Peek in November 2024, threat actors exploited CVE-2024-0012 and CVE-2024-9474 together to achieve unauthenticated remote admin access across exposed management interfaces. Palo Alto Networks scored the vulnerabilities at 9.3 and 6.9 under CVSS v4.0, while the National Vulnerability Database rated them 9.8 and 7.2 under CVSS v3.1.
The 6.9 score fell below patch thresholds at many organizations. Security teams dismissed the escalation flaw because it appeared to require admin access when evaluated individually.
The Shadowserver Foundation identified over 2,000 compromised Palo Alto Networks firewalls. Censys found 13,324 publicly exposed next-generation firewall management interfaces as of November 18, 2024, with 34% located in the United States.
The highest number of affected devices were in the U.S. (554) and India (461), followed by Thailand (80), Mexico (48), Indonesia (43), Turkey (41), the U.K. (39), Peru (36), and South Africa (35).
Security researcher Yutaka Sejiyama discovered 15,429 public-facing servers globally running Palo Alto Networks’ management interface via Shodan. Among these, 11,180 were confirmed as active.
The attack highlights fundamental problems with vulnerability scoring systems. Peter Chronis, former CISO of Paramount, wrote that CVSS base scores are theoretical measures that ignore real-world context. By moving beyond CVSS-first prioritization at Paramount, Chronis reduced actionable critical and high-risk vulnerabilities by 90%.
Chris Gibson, executive director of FIRST, the organization that maintains CVSS, told The Register that using CVSS base scores alone for prioritization is the least apt and accurate method.
Adam Meyers, SVP of Counter Adversary Operations at CrowdStrike, said adversaries circumvent severity ratings by chaining vulnerabilities together. On the triage logic that missed the chain, Meyers said they just had amnesia from 30 seconds before.
The problem is growing worse. In 2025, 48,185 CVEs were disclosed, a 20.6% year-over-year increase. Jerry Gamblin, principal engineer at Cisco Threat Detection and Response, projects 70,135 for 2026.
The CrowdStrike 2026 Global Threat Report documented a 42% year-over-year increase in vulnerabilities exploited as zero-days before public disclosure. Average breakout time across observed intrusions was 29 minutes. The fastest observed breakout took 27 seconds.
China-nexus adversaries weaponized newly patched vulnerabilities within two to six days of disclosure.
Artificial intelligence is accelerating vulnerability discovery. Anthropic’s Claude Mythos Preview demonstrated autonomous vulnerability discovery, finding a 27-year-old signed integer overflow in OpenBSD’s TCP SACK implementation across roughly 1,000 scaffold runs at a total compute cost under $20,000.
Meyers projected that if frontier AI drives a 10x volume increase, the result would be approximately 480,000 CVEs annually. Pipelines built for 48,000 break at 70,000 and collapse at 480,000.
CrowdStrike launched Project QuiltWorks, an industry coalition powered by frontier models from OpenAI and Anthropic. The project includes Accenture, EY, IBM Cybersecurity Services, Kroll, and OpenAI to close the AI vulnerability gap.
Daniel Bernard, Chief Business Officer at CrowdStrike, said the new reality means patching every day, all the time, rather than once monthly Patch Tuesday cycles.
This article was written by an AI agent. Spotted an error? Send a correction and we will fix it.
