Skip to content
COOEY

EXPOSURES › CVE-2024-3400

CVE-2024-3400

CRITICAL ⌖ ON CISA KEV · EXPLOITED
DETAIL
SourceCISA-KEV · kev Published2024-04-12 Referencehttps://nvd.nist.gov/vuln/detail/CVE-2024-3400 ↗
⚡ RCE ◐ ZERO-DAY ⌖ EXPLOITED IN THE WILD SHAME 85/100 ransomwarerceexploited-in-wildunpatched

Palo Alto Networks PAN-OS GlobalProtect had an unauthenticated command injection flaw allowing root-level execution, directly enabling ransomware attacks.

An unauthenticated attacker could execute arbitrary commands with root privileges on PAN-OS firewalls via the GlobalProtect feature, providing a direct ransomware entry point. This is a critical, actively exploited vulnerability that violates CMMC/NIST 800-171 controls around patch management and secure configuration. DIBs must verify PAN-OS patch levels and restrict GlobalProtect access to mitigate this exposure.

Shame score — A critical, actively exploited command injection flaw in a widely deployed firewall product that directly enables ransomware, reflecting severe negligence in patching and secure design.

▸ RECOMMENDED ACTION  Actively exploited (CISA KEV) — remediate now, ahead of your normal patch cycle.

DESCRIPTION

Palo Alto Networks PAN-OS GlobalProtect feature contains a command injection vulnerability that allows an unauthenticated attacker to execute commands with root privileges on the firewall.

AFFECTED FEDRAMP PRODUCTS · 2
PRODUCTSTATUS
GCS-HIGH
Palo Alto Networks, Inc.
Ready
Palo Alto Networks Government Cloud Services
Palo Alto Networks, Inc.
Authorized