CVE-2024-3400KEV · OVERDUECWE-20CWE-77

PAN-OS: Arbitrary File Creation Leads to OS Command Injection Vulnerability in GlobalProtect

Critical · published April 12, 2024

Patch now

Confirmed exploited, and the score agrees

CVSS calls it critical at 10.0. It is confirmed in active exploitation. It sits in the 100.0th percentile for exploit probability.

870
days past CISA
deadline
CVSS v3.1
10.0
EPSS
100%
Percentile
100.0
In the wild
Confirmed
What it is

🚨 An unauthenticated attacker can run arbitrary code on your firewall like it’s a playground swing! This command injection vulnerability in Palo Alto Networks PAN-OS is a serious threat—time to take action! 🔥 Think of your firewall as a high-security vault. If a crafty thief finds a way to create a new key (by exploiting this command injection), they could waltz right in and access everything inside—a nightmare for your digital assets! An attacker can execute any code as a root user on the firewall, potentially leading to a complete compromise of your network’s security. This could mean unauthorized access to sensitive data, manipulation of configurations, and even full control over your network. The implications are absolutely devastating!

Put simply

Think of your firewall as a high-security vault. If a crafty thief finds a way to create a new key (by exploiting this command injection), they could waltz right in and access everything inside—a nightmare for your digital assets! This command injection vulnerability arises from a flaw in the GlobalProtect feature of specific PAN-OS versions which allows attackers to create arbitrary files. When this happens, they can execute code with root privileges, bypassing all security measures.

What to do

An attacker can execute any code as a root user on the firewall, potentially leading to a complete compromise of your network’s security. This could mean unauthorized access to sensitive data, manipulation of configurations, and even full control over your network. The implications are absolutely devastating! Immediately patch your PAN-OS to the latest version as per Palo Alto's guidance, ensuring you are not running any impacted configurations. Audit your system for any signs of exploitation, and reinforce your firewall rules. Staying proactive is key! You've got this! Patch your systems and lock down your firewalls—your security hero status is activated! 🛡️

The record
Technical detail
CVSS v3.1
10.0 · CRITICAL
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H
CVSS v4.0
Not supplied
EPSS
0.99999 · 100.0th percentile
Weaknesses
CWE-20 · Improper Input Validation; CWE-77 · Improper Neutralization of Special Elements used in a Command ('Command Injection')
Published
2024-04-12T07:20Z
KEV added
2024-04-12 · due 2024-04-19
EPSS history
Timeline
  • 12 APR 07:20Z
    PAN-OS: Arbitrary File Creation Leads to OS Command Injection Vulnerability in GlobalProtect
    cvelistv5
  • 12 APR 00:00Z
    Added to CISA KEV — remediate by Apr 19
    kev