CRITICAL

CVE-2024-3400

Paloaltonetworks Pan Os 2024-04-12 CVSS v3.1
CVSS
10
KEV

Description

A command injection as a result of arbitrary file creation vulnerability in the GlobalProtect feature of Palo Alto Networks PAN-OS software for specific PAN-OS versions and distinct feature configurations may enable an unauthenticated attacker to execute arbitrary code with root privileges on the firewall.

Cloud NGFW, Panorama appliances, and Prisma Access are not impacted by this vulnerability.

Summary dbcve.org

A command injection vulnerability in the GlobalProtect feature of Palo Alto Networks PAN-OS allows unauthenticated attackers to execute arbitrary code with root privileges. The flaw stems from arbitrary file creation that can be leveraged to inject commands into the firewall's operating system, affecting specific PAN-OS versions with GlobalProtect enabled.

Mitigation

Immediately identify and upgrade affected PAN-OS installations to the vendor-provided patched versions. If immediate patching is not feasible, consider disabling GlobalProtect or implementing network-level mitigations such as restricting access to the GlobalProtect interface.

Proof of Concept

Weakness (CWE)

CWE-20 Improper Input Validation
CWE-77 Command Injection

EPSS Score

100%
Probability of exploitation in next 30 days
100th percentile

References

View on dbcve.org
Base CVE data derived from NVD (public domain). Enrichment by dbcve.org (CC-BY-4.0). Fetched via API.
Back to CVE