CVE-2024-3400

Confirmed PUBLISHED

PAN-OS: Arbitrary File Creation Leads to OS Command Injection Vulnerability in GlobalProtect

Palo Alto Networks · PAN-OS, Cloud NGFW, Prisma Access
Exploited in the wild Used in malware PoC available

Recommended Action

Prioritize remediation. Validate affected assets and apply vendor fixes on an accelerated timeline.

Confidence
Confirmed
Exploitation Status
Exploited in the wild
Observed in Sensors
No
Attempts (30d)
Unique Attacker IPs
CISA KEV
In CISA KEV
CVSS / EPSS
10.0 Critical EPSS 100.0%

At a Glance

A command injection as a result of arbitrary file creation vulnerability in the GlobalProtect feature of Palo Alto Networks PAN-OS software for specific PAN-OS versions and distinct feature configurations may enable an unauthenticated attacker to execute arbitrary code with root privileges on the firewall. Cloud NGFW, Panorama appliances, and Prisma Access are not impacted by this vulnerability.

ransomware nuclei_scanner metasploit edge nessus_scanner malware cisa
CVE Published
Apr 12, 2024
Exploitation Reported
Apr 12, 2024
CVSS
10.0 Critical
EPSS
100.0%
Remote Low complexity No user interaction Unauthenticated

Affected Versions

Vendor Product Version Status
paloaltonetworks
pan-os

10.2.0 to < 10.2.9-h1

Affected
paloaltonetworks
pan-os

11.0.0 to < 11.0.4-h1

Affected
paloaltonetworks
pan-os

11.1.0 to < 11.1.2-h3

Affected
Palo Alto Networks
PAN-OS

9.0.0

Unaffected
Palo Alto Networks
PAN-OS

9.1.0

Unaffected
Palo Alto Networks
PAN-OS

10.0.0

Unaffected
Palo Alto Networks
PAN-OS

10.1.0

Unaffected
Palo Alto Networks
PAN-OS

10.2.0 to < 10.2.9-h1

Changed to unaffected at 10.2.9-h1

Affected
Palo Alto Networks
PAN-OS

11.0.0 to < 11.0.4-h1

Changed to unaffected at 11.0.4-h1

Affected
Palo Alto Networks
PAN-OS

11.1.0 to < 11.1.2-h3

Changed to unaffected at 11.1.2-h3

Affected
Palo Alto Networks
Cloud NGFW

All

Unaffected
Palo Alto Networks
Prisma Access

All

Unaffected

CVE References

Recommended Actions

  • Prioritize remediation. Validate affected assets and apply vendor fixes on an accelerated timeline.
  • Check enrichment artifacts for scanner coverage and available PoCs before rolling remediation validation.
  • Use the Pro API to automate enrichment, telemetry, and workflow delivery for VM, SOC, and CTI pipelines.