Junglewise Threat Intelligence

CVE-2024-3400: Palo Alto Networks PAN-OS Command Injection Vulnerability

CVE-2024-3400 · Severity: critical · CVSS 10 · Exploited in the wild · Published 2024-04-12

Technologies: Palo Alto Networks PAN-OS. Vendors: Palo Alto Networks, Palo Alto Networks.

Executive brief

A command injection vulnerability in the GlobalProtect feature of Palo Alto Networks PAN-OS allows an unauthenticated network-based attacker to execute arbitrary code with root privileges. The flaw stems from arbitrary file creation and impacts specific PAN-OS versions and configurations.

Affected products

  • Palo Alto Networks PAN-OS 10.2 and other specific versions with GlobalProtect enabled

Timeline

  • 2024-04-12: disclosed
  • 2024-04-12: exploited: Reported as exploited in the wild by Volexity and CISA.
  • 2024-04-12: kev added: Added to CISA Known Exploited Vulnerabilities Catalog.

Related threats