EXPOSURES › CVE-2024-3400
CVE-2024-3400
CRITICAL ⌖ ON CISA KEV · EXPLOITEDPalo Alto Networks PAN-OS GlobalProtect had an unauthenticated command injection flaw allowing root-level execution, directly enabling ransomware attacks.
An unauthenticated attacker could execute arbitrary commands with root privileges on PAN-OS firewalls via the GlobalProtect feature, providing a direct ransomware entry point. This is a critical, actively exploited vulnerability that violates CMMC/NIST 800-171 controls around patch management and secure configuration. DIBs must verify PAN-OS patch levels and restrict GlobalProtect access to mitigate this exposure.
Shame score — A critical, actively exploited command injection flaw in a widely deployed firewall product that directly enables ransomware, reflecting severe negligence in patching and secure design.
▸ RECOMMENDED ACTION Actively exploited (CISA KEV) — remediate now, ahead of your normal patch cycle.
Palo Alto Networks PAN-OS GlobalProtect feature contains a command injection vulnerability that allows an unauthenticated attacker to execute commands with root privileges on the firewall.
| PRODUCT | STATUS |
|---|---|
| GCS-HIGH Palo Alto Networks, Inc. |
Ready |
| Palo Alto Networks Government Cloud Services Palo Alto Networks, Inc. |
Authorized |