← Vulnerability feed

Vulnerability record · CVE-2024-3400 · published 12 April 2024

CVE-2024-3400: PAN-OS GlobalProtect command injection allows unauthenticated root code execution

Paloaltonetworks · Pan Os

A command injection caused by arbitrary file creation in the GlobalProtect feature of Palo Alto Networks PAN-OS lets an unauthenticated attacker run arbitrary code as root on the firewall. Only specific PAN-OS versions and feature configurations are affected; Cloud NGFW, Panorama appliances and Prisma Access are not impacted. Because the target is an internet-facing security appliance, compromise gives an attacker a privileged foothold at the network edge.

10.0 CVSS 3.1 Critical CISA KEV since 12 Apr 2024 Known ransomware use EPSS 100% · top 0.1% CWE-20 · Improper input validationCWE-77 · Command injection
10.0CVSS 3.1 base score
100%EPSS exploitation probability, 30 days
YesIn CISA KEV, fix deadline passed
1Affected product versions listed by NVD
9References, 4 tagged exploit
17 Jun 2026Last modified by NVD

Description

A command injection as a result of arbitrary file creation vulnerability in the GlobalProtect feature of Palo Alto Networks PAN-OS software for specific PAN-OS versions and distinct feature configurations may enable an unauthenticated attacker to execute arbitrary code with root privileges on the firewall. Cloud NGFW, Panorama appliances, and Prisma Access are not impacted by this vulnerability.

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H

Automated analysis

Generated by VULONE's analysis model from the NVD record, CISA KEV and EPSS data on 16 September 2026. Confidence: high.

critical priorityUnauthenticated remote root code execution on an internet-facing firewall, actively exploited as a zero-day, in CISA KEV with ransomware use noted and an EPSS near 1.0.

What it is

A command injection caused by arbitrary file creation in the GlobalProtect feature of Palo Alto Networks PAN-OS lets an unauthenticated attacker run arbitrary code as root on the firewall. Only specific PAN-OS versions and feature configurations are affected; Cloud NGFW, Panorama appliances and Prisma Access are not impacted. Because the target is an internet-facing security appliance, compromise gives an attacker a privileged foothold at the network edge.

Impact

An attacker gains root-level code execution on the firewall, allowing full control of the device and its traffic handling. That position can be used to intercept or alter network traffic and to pivot into protected internal networks.

Attack surface

Reachable over the network through the GlobalProtect feature with no authentication and no user interaction required, per the CVSS vector AV:N/AC:L/PR:N/UI:N. Only devices running the affected PAN-OS versions with the relevant GlobalProtect configuration are exposed.

Exploitation

Exploited in the wild as a zero-day, listed in CISA KEV on 2024-04-12 with a 2024-04-19 remediation due date and flagged for known ransomware campaign use. EPSS is 0.99999 (100th percentile), and vendor and third-party references are tagged as exploit write-ups.

What to do

  • Apply the PAN-OS patch from the vendor advisory as soon as it is available for your version.
  • If patching is not immediately possible, enable the vendor-provided Threat Prevention IDs as directed in the CISA KEV required action and vendor bulletin.
  • Restrict or disable GlobalProtect access from untrusted networks until the device is patched.
  • Check the vendor advisory to confirm whether your specific PAN-OS version and GlobalProtect configuration are affected, since only distinct configurations are vulnerable.
  • Treat any internet-exposed, unpatched GlobalProtect interface as compromised and review it for signs of intrusion.

Detection

  • Hunt firewall and GlobalProtect logs for unusual requests or file creation activity preceding command execution.
  • Monitor for unexpected outbound connections or new processes on PAN-OS management and dataplane interfaces.
  • Review the vendor and Unit 42 threat research for indicators of compromise and search logs for those patterns.
  • Alert on configuration or file changes on the firewall outside of approved change windows.

This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.

Exploitation in the wild

CISA added CVE-2024-3400 to the Known Exploited Vulnerabilities catalog on 12 April 2024 as "Palo Alto Networks PAN-OS Command Injection Vulnerability". CISA reports known use in ransomware campaigns. Required action: Apply mitigations per vendor instructions as they become available. Otherwise, users with vulnerable versions of affected devices should enable Threat Prevention IDs available from the vendor. See the vendor bulletin for more details and a patch release schedule. Federal deadline 19 April 2024.

Affected products

1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

Track CVE-2024-3400 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

10.0CVE-2020-2021PAN-OS SAML signature verification bypass allows authentication bypassPAN-OS fails to properly verify SAML signatures when SAML authentication is enabled and the 'Validate Identity Provider Certificate' option is unchec…KEVEPSS 4.4%analysed9.8CVE-2017-15944PAN-OS management interface input validation flaw allows remote code executionPAN-OS versions before 6.1.19, 7.0.x before 7.0.19, 7.1.x before 7.1.14, and 8.0.x before 8.0.6 contain an input validation and memory buffer overflo…KEVEPSS 98%analysed9.3CVE-2026-0300PAN-OS User-ID Authentication Portal buffer overflow allows root code executionA buffer overflow (out-of-bounds write, CWE-787) in the User-ID Authentication Portal (Captive Portal) service of Palo Alto Networks PAN-OS lets an u…KEVEPSS 32%analysed9.3CVE-2024-0012PAN-OS Management Web Interface Authentication BypassPAN-OS contains a missing authentication flaw (CWE-306) in the management web interface that lets an unauthenticated network attacker obtain PAN-OS a…KEVEPSS 100%analysed8.8CVE-2025-0108PAN-OS management web interface authentication bypassPAN-OS contains a missing-authentication flaw (CWE-306) in the management web interface that lets an unauthenticated attacker with network access inv…KEVEPSS 98%analysed8.7CVE-2024-3393PAN-OS DNS Security packet causes firewall reboot and maintenance modeA denial of service flaw in the DNS Security feature of Palo Alto Networks PAN-OS lets an unauthenticated attacker send a crafted packet through the …KEVEPSS 28%analysed8.6CVE-2022-0028PAN-OS URL filtering misconfiguration enables reflected TCP DoSA PAN-OS URL filtering policy misconfiguration allows a network-based attacker to use PA-Series, VM-Series and CN-Series firewalls to conduct reflect…KEVEPSS 2.4%analysed8.1CVE-2019-1579PAN-OS GlobalProtect pre-auth remote code executionPAN-OS versions 7.1.18, 8.0.11-h1 and 8.1.2 and earlier contain a remote code execution flaw (CWE-134, format string) that is reachable when the Glob…KEVEPSS 46%analysed

Source: NIST National Vulnerability Database (record CVE-2024-3400), CISA KEV, FIRST EPSS (scores of 2026-09-16). This page is refreshed as NVD updates the record.