Security Bulletin

CVE-2024-3400: Palo Alto Networks Command Injection Vulnerability

Bulletin: a critical command-injection vulnerability in the GlobalProtect feature of Palo Alto Networks PAN-OS — risk profile, affected versions, and mitigation guidance.

On Friday, April 12, 2024, Palo Alto Networks published an advisory on CVE-2024-3400, a CVSS-10 zero-day vulnerability in several versions of PAN-OS, the operating system that runs the company's firewalls. At time of publication this vulnerability was unpatched, with fixes expected by Sunday, April 14, 2024.

CVE-2024-3400 details

  • Severity: Critical — CVSS 10/10
  • Exploitation status: Exploited in the wild in a limited number of attacks (per Palo Alto Networks' advisory)
  • CVE ID: CVE-2024-3400

Impact

If you are a Palo Alto Networks customer running PAN-OS 10.2, 11.0, or 11.1 with both GlobalProtect gateway and device telemetry enabled, the vulnerability allows an unauthenticated attacker to execute arbitrary code with root privileges on the firewall.

Affected products

Version Affected Unaffected
Cloud Next-Gen FirewallNoneAll
PAN-OS 11.1< 11.1.2-h3≥ 11.1.2-h3 (ETA: 4/14)
PAN-OS 11.0< 11.0.4-h1≥ 11.0.4-h1 (ETA: 4/14)
PAN-OS 10.2< 10.2.9-h1≥ 10.2.9-h1 (ETA: 4/14)
PAN-OS 10.1NoneAll
PAN-OS 10.0NoneAll
PAN-OS 9.1NoneAll
PAN-OS 9.0NoneAll
Prisma AccessNoneAll

Recommendations

Fixes for PAN-OS 10.2, 11.0, and 11.1 are in development and expected by April 14, 2024. Cloud NGFW, Panorama appliances, and Prisma Access are not impacted. The issue applies only to PAN-OS 10.2, 11.0, and 11.1 firewalls with both GlobalProtect gateway and device telemetry enabled.

You can verify a GlobalProtect gateway is configured by checking the firewall web interface (Network → GlobalProtect → Gateways), and verify device telemetry is enabled at Device → Setup → Telemetry.

References

  1. Palo Alto Networks Advisory
  2. How to Disable Device Telemetry in Palo Alto Network Devices

What Digital Hands is doing

For managed customers, Digital Hands is identifying devices with a vulnerable configuration. Where one is found, we will download Applications and Threats content version 8833-8682 (which contains Threat ID 95187) to block exploitation attempts. The vulnerability will be addressed in the hotfix releases (ETA 4/14) and in all subsequent PAN-OS versions:

  • PAN-OS 10.2.9-h1
  • PAN-OS 11.0.4-h1
  • PAN-OS 11.1.2-h3

Once hotfixes are released, we work with customers to schedule upgrades. If you are not a Digital Hands managed customer, follow the directions in the Palo Alto Networks advisory. Talk to a Cyber Expert if you'd like Digital Hands to monitor your environment for the next zero-day.

Back to Blog

Ready to Get There First?

Talk to a Cyber Expert