Vulnerability record · CVE-2024-3400 · published 12 April 2024
CVE-2024-3400: PAN-OS GlobalProtect command injection allows unauthenticated root code execution
Paloaltonetworks · Pan Os
A command injection caused by arbitrary file creation in the GlobalProtect feature of Palo Alto Networks PAN-OS lets an unauthenticated attacker run arbitrary code as root on the firewall. Only specific PAN-OS versions and feature configurations are affected; Cloud NGFW, Panorama appliances and Prisma Access are not impacted. Because the target is an internet-facing security appliance, compromise gives an attacker a privileged foothold at the network edge.
Description
A command injection as a result of arbitrary file creation vulnerability in the GlobalProtect feature of Palo Alto Networks PAN-OS software for specific PAN-OS versions and distinct feature configurations may enable an unauthenticated attacker to execute arbitrary code with root privileges on the firewall. Cloud NGFW, Panorama appliances, and Prisma Access are not impacted by this vulnerability.
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H
Automated analysis
critical priorityUnauthenticated remote root code execution on an internet-facing firewall, actively exploited as a zero-day, in CISA KEV with ransomware use noted and an EPSS near 1.0.
What it is
A command injection caused by arbitrary file creation in the GlobalProtect feature of Palo Alto Networks PAN-OS lets an unauthenticated attacker run arbitrary code as root on the firewall. Only specific PAN-OS versions and feature configurations are affected; Cloud NGFW, Panorama appliances and Prisma Access are not impacted. Because the target is an internet-facing security appliance, compromise gives an attacker a privileged foothold at the network edge.
Impact
An attacker gains root-level code execution on the firewall, allowing full control of the device and its traffic handling. That position can be used to intercept or alter network traffic and to pivot into protected internal networks.
Attack surface
Reachable over the network through the GlobalProtect feature with no authentication and no user interaction required, per the CVSS vector AV:N/AC:L/PR:N/UI:N. Only devices running the affected PAN-OS versions with the relevant GlobalProtect configuration are exposed.
Exploitation
Exploited in the wild as a zero-day, listed in CISA KEV on 2024-04-12 with a 2024-04-19 remediation due date and flagged for known ransomware campaign use. EPSS is 0.99999 (100th percentile), and vendor and third-party references are tagged as exploit write-ups.
What to do
- Apply the PAN-OS patch from the vendor advisory as soon as it is available for your version.
- If patching is not immediately possible, enable the vendor-provided Threat Prevention IDs as directed in the CISA KEV required action and vendor bulletin.
- Restrict or disable GlobalProtect access from untrusted networks until the device is patched.
- Check the vendor advisory to confirm whether your specific PAN-OS version and GlobalProtect configuration are affected, since only distinct configurations are vulnerable.
- Treat any internet-exposed, unpatched GlobalProtect interface as compromised and review it for signs of intrusion.
Detection
- Hunt firewall and GlobalProtect logs for unusual requests or file creation activity preceding command execution.
- Monitor for unexpected outbound connections or new processes on PAN-OS management and dataplane interfaces.
- Review the vendor and Unit 42 threat research for indicators of compromise and search logs for those patterns.
- Alert on configuration or file changes on the firewall outside of approved change windows.
This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.
Exploitation in the wild
CISA added CVE-2024-3400 to the Known Exploited Vulnerabilities catalog on 12 April 2024 as "Palo Alto Networks PAN-OS Command Injection Vulnerability". CISA reports known use in ransomware campaigns. Required action: Apply mitigations per vendor instructions as they become available. Otherwise, users with vulnerable versions of affected devices should enable Threat Prevention IDs available from the vendor. See the vendor bulletin for more details and a patch release schedule. Federal deadline 19 April 2024.
Affected products
1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.
References
| Link | Tags |
|---|---|
| https://security.paloaltonetworks.com/CVE-2024-3400 | Vendor Advisory |
| https://unit42.paloaltonetworks.com/cve-2024-3400/ | ExploitVendor Advisory |
| https://www.paloaltonetworks.com/blog/2024/04/more-on-the-pan-os-cve/ | Technical DescriptionVendor Advisory |
| https://www.volexity.com/blog/2024/04/12/zero-day-exploitation-of-unauthenticated-remote-code-execution-vulnerability-in | ExploitThird Party Advisory |
| https://security.paloaltonetworks.com/CVE-2024-3400 | Vendor Advisory |
| https://unit42.paloaltonetworks.com/cve-2024-3400/ | ExploitVendor Advisory |
| https://www.paloaltonetworks.com/blog/2024/04/more-on-the-pan-os-cve/ | Technical DescriptionVendor Advisory |
| https://www.volexity.com/blog/2024/04/12/zero-day-exploitation-of-unauthenticated-remote-code-execution-vulnerability-in | ExploitThird Party Advisory |
| https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2024-3400 | US Government Resource |
Track CVE-2024-3400 inside VULONE
Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.
Related vulnerabilities
Same products first, then exploited flaws of the same weakness class.
Source: NIST National Vulnerability Database (record CVE-2024-3400), CISA KEV, FIRST EPSS (scores of 2026-09-16). This page is refreshed as NVD updates the record.