Critical - CVSS 9.8
Known Ransomware Use
Added 4/12/2024

Palo Alto Networks PAN-OS Command Injection Vulnerability

CVE-2024-3400
Action was due by: 4/19/2024
CISA Known Exploited Vulnerability

This vulnerability is part of CISA's Known Exploited Vulnerabilities (KEV) catalog, indicating active exploitation in the wild. It has been observed in ransomware campaigns.

Overview

Palo Alto Networks PAN-OS GlobalProtect feature contains a command injection vulnerability that allows an unauthenticated attacker to execute commands with root privileges on the firewall.

Vendor

Palo Alto Networks

Product

PAN-OS

Category

Software
Technical Details

Affected Versions

See vendor advisory

Technical Description

This vulnerability was identified in PAN-OS by Palo Alto Networks. Palo Alto Networks PAN-OS GlobalProtect feature contains a command injection vulnerability that allows an unauthenticated attacker to execute commands with root privileges on the firewall.

Exploitability

High - Known ransomware exploitation

Impact

Complete system compromise possible

Additional Notes

https://security.paloaltonetworks.com/CVE-2024-3400 ; https://nvd.nist.gov/vuln/detail/CVE-2024-3400

Required Action (CISA)

Apply mitigations per vendor instructions as they become available. Otherwise, users with vulnerable versions of affected devices should enable Threat Prevention IDs available from the vendor. See the vendor bulletin for more details and a patch release schedule.

Due Date: 4/19/2024