On Friday, April 12, 2024, Palo Alto Networks published an advisory on CVE-2024-3400, a CVSS-10 zero-day vulnerability in several versions of PAN-OS, the operating system that runs the company's firewalls. At time of publication this vulnerability was unpatched, with fixes expected by Sunday, April 14, 2024.
CVE-2024-3400 details
- Severity: Critical — CVSS 10/10
- Exploitation status: Exploited in the wild in a limited number of attacks (per Palo Alto Networks' advisory)
- CVE ID: CVE-2024-3400
Impact
If you are a Palo Alto Networks customer running PAN-OS 10.2, 11.0, or 11.1 with both GlobalProtect gateway and device telemetry enabled, the vulnerability allows an unauthenticated attacker to execute arbitrary code with root privileges on the firewall.
Affected products
| Version | Affected | Unaffected |
|---|---|---|
| Cloud Next-Gen Firewall | None | All |
| PAN-OS 11.1 | < 11.1.2-h3 | ≥ 11.1.2-h3 (ETA: 4/14) |
| PAN-OS 11.0 | < 11.0.4-h1 | ≥ 11.0.4-h1 (ETA: 4/14) |
| PAN-OS 10.2 | < 10.2.9-h1 | ≥ 10.2.9-h1 (ETA: 4/14) |
| PAN-OS 10.1 | None | All |
| PAN-OS 10.0 | None | All |
| PAN-OS 9.1 | None | All |
| PAN-OS 9.0 | None | All |
| Prisma Access | None | All |
Recommendations
Fixes for PAN-OS 10.2, 11.0, and 11.1 are in development and expected by April 14, 2024. Cloud NGFW, Panorama appliances, and Prisma Access are not impacted. The issue applies only to PAN-OS 10.2, 11.0, and 11.1 firewalls with both GlobalProtect gateway and device telemetry enabled.
You can verify a GlobalProtect gateway is configured by checking the firewall web interface (Network → GlobalProtect → Gateways), and verify device telemetry is enabled at Device → Setup → Telemetry.
References
What Digital Hands is doing
For managed customers, Digital Hands is identifying devices with a vulnerable configuration. Where one is found, we will download Applications and Threats content version 8833-8682 (which contains Threat ID 95187) to block exploitation attempts. The vulnerability will be addressed in the hotfix releases (ETA 4/14) and in all subsequent PAN-OS versions:
- PAN-OS 10.2.9-h1
- PAN-OS 11.0.4-h1
- PAN-OS 11.1.2-h3
Once hotfixes are released, we work with customers to schedule upgrades. If you are not a Digital Hands managed customer, follow the directions in the Palo Alto Networks advisory. Talk to a Cyber Expert if you'd like Digital Hands to monitor your environment for the next zero-day.