CVE-2024-3400 KEV EXPLOIT
10.0
CRITICAL · CVSS 3.1 · EPSS 100% (pctl 100)
Patch first
On CISA KEV — known exploited in the wild, due 2024-04-19.
Description
A command injection as a result of arbitrary file creation vulnerability in the GlobalProtect feature of Palo Alto Networks PAN-OS software for specific PAN-OS versions and distinct feature configurations may enable an unauthenticated attacker to execute arbitrary code with root privileges on the firewall. Cloud NGFW, Panorama appliances, and Prisma Access are not impacted by this vulnerability.
Scoring
| CVSS | 10.0 (CRITICAL, v3.1) |
|---|---|
| Vector | CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H |
| EPSS | 100% — more likely to be exploited than 100% of all CVEs |
| Weakness | CWE-20 |
| On CISA KEV | yes — remediate by 2024-04-19 |
| Public exploit | yes |
| Published | 2024-04-12 |
| Last modified | 2026-06-17 |
CISA KEV
| Name | Palo Alto Networks PAN-OS Command Injection Vulnerability |
|---|---|
| Added | 2024-04-12 |
| Due | 2024-04-19 |
| Vendor / product | Palo Alto Networks / PAN-OS |
| Ransomware use | known |
Affected (1)
| Vendor | Product |
|---|---|
| paloaltonetworks | pan-os |
Public exploits
| Source | Title | Date |
|---|---|---|
| exploit-db | Palo Alto PAN-OS < v11.1.2-h3 - Command Injection and Arbitrary File Creation | 2024-04-21 |
References
- https://security.paloaltonetworks.com/CVE-2024-3400
- https://unit42.paloaltonetworks.com/cve-2024-3400/
- https://www.paloaltonetworks.com/blog/2024/04/more-on-the-pan-os-cve/
- https://www.volexity.com/blog/2024/04/12/zero-day-exploitation-of-unauthenticated-remote-code-execution-vulnerability-in-globalprotect-cve-2024-3400/
- https://security.paloaltonetworks.com/CVE-2024-3400
- https://unit42.paloaltonetworks.com/cve-2024-3400/
- https://www.paloaltonetworks.com/blog/2024/04/more-on-the-pan-os-cve/
- https://www.volexity.com/blog/2024/04/12/zero-day-exploitation-of-unauthenticated-remote-code-execution-vulnerability-in-globalprotect-cve-2024-3400/
- https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2024-3400
→ the Explorer · watch your stack · NVD