CVE-2024-3400

Published Apr 12, 2024

Last updated 5 months ago

Analyzed

Description

A command injection as a result of arbitrary file creation vulnerability in the GlobalProtect feature of Palo Alto Networks PAN-OS software for specific PAN-OS versions and distinct feature configurations may enable an unauthenticated attacker to execute arbitrary code with root privileges on the firewall. Cloud NGFW, Panorama appliances, and Prisma Access are not impacted by this vulnerability.

Insights

Analysis from the Intruder Security Team Published Oct 15, 2024

The serious vulnerability affects a number of Palo Alto GlobalProtect devices which utilize device analytics. Active exploitation of this vulnerability has been witnessed by a number of organizations.

More information is available in our blog post here.

Risk scores

CVSS 3.1

Primary
10
6
3.9
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H
CRITICAL

Known exploits

Data from CISA

Palo Alto Networks PAN-OS Command Injection Vulnerability

Apr 12, 2024

Apr 19, 2024

Apply mitigations per vendor instructions as they become available. Otherwise, users with vulnerable versions of affected devices should enable Threat Prevention IDs available from the vendor. See the vendor bulletin for more details and a patch release schedule.

Weaknesses

CWE-77
CWE-20

Source

psirt@paloaltonetworks.com

Configurations