Back to overview

CVE-2024-3400

CRITICAL KEV CISA Exploitation: ACTIVE Ransomware noto
10.0
CVSS 3.1
Description
A command injection as a result of arbitrary file creation vulnerability in the GlobalProtect feature of Palo Alto Networks PAN-OS software for specific PAN-OS versions and distinct feature configurations may enable an unauthenticated attacker to execute arbitrary code with root privileges on the firewall. Cloud NGFW, Panorama appliances, and Prisma Access are not impacted by this vulnerability.

Metadata

CVE ID
CVE-2024-3400
State
PUBLISHED
Assigner
palo_alto
Reserved
2024-04-05 17:40 UTC
Published
2024-04-12 07:20 UTC
Last updated
2025-10-21 23:05 UTC
Primary CWE
CWE-77
CWE-77 Improper Neutralization of Special Elements used in a…
Vendor / Product
Palo Alto Networks / PAN-OS
Sources
cve.org  ·  NVD

Severity & Metrics

10.0 CRITICAL CVSS 3.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H
SSVC — CISA Coordinator
Exploitation
ACTIVE
Automatable
yes
Tech. Impact
total
CISA Known Exploited Vulnerability
Vulnerability name
Palo Alto Networks PAN-OS Command Injection Vulnerability
Vendor
Palo Alto Networks
Product
PAN-OS
Added to KEV
2024-04-12
Due date
2024-04-19
Ransomware
Known use
Required action
Apply mitigations per vendor instructions as they become available. Otherwise, users with vulnerable versions of affected devices should enable Threat Prevention IDs available from the vendor. See the vendor bulletin for more details and a patch release schedule.
CISA description
Palo Alto Networks PAN-OS GlobalProtect feature contains a command injection vulnerability that allows an unauthenticated attacker to execute commands with root privileges on the firewall.
Affected products (3)
VendorProductPlatformVersions
Palo Alto Networks Cloud NGFW All
Palo Alto Networks PAN-OS 9.0.0, 9.1.0, 10.0.0, 10.1.0 …
Palo Alto Networks Prisma Access All
Weakness (CWE)
CWESourceDescription
CWE-20 cna CWE-20 Improper Input Validation
CWE-77 cna CWE-77 Improper Neutralization of Special Elements used in a Command ('Command Injection')
CVSS scores (1)
ScoreSeverityVersionSourceVector
10.0 CRITICAL 3.1 cna CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H
Back to overview