PAN-OS: Arbitrary File Creation Leads to OS Command Injection Vulnerability in GlobalProtect
- Sévérité
- Critique10CVSS 3.1, Critique
- EPSS
- 100 %
- Publiée
- 12 avr. 2024
- Mise à jour
- 17 juin 2026
Description
Le titre, la description et les consignes de l’éditeur sont cités depuis les enregistrements sources (en anglais).
A command injection as a result of arbitrary file creation vulnerability in the GlobalProtect feature of Palo Alto Networks PAN-OS software for specific PAN-OS versions and distinct feature configurations may enable an unauthenticated attacker to execute arbitrary code with root privileges on the firewall. Cloud NGFW, Panorama appliances, and Prisma Access are not impacted by this vulnerability.
Faiblesse : CWE-77, CWE-20
Exploitée activement
Ajoutée au catalogue CISA KEV le 12 avr. 2024
Date limite de remédiation fédérale : 19 avr. 2024
Utilisation connue par des rançongiciels
Action requise : Apply mitigations per vendor instructions as they become available. Otherwise, users with vulnerable versions of affected devices should enable Threat Prevention IDs available from the vendor. See the vendor bulletin for more details and a patch release schedule.
Prédiction d’exploitation
Probabilité d’exploitation de 100 % dans les 30 prochains jours (percentile 100 %).
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H
Ce qu’indique la source, par branche
Versions comparées par Patcharo
Palo Alto Networks PAN-OSSource : Palo Alto Networks (CVE record)
| Branche | Affectées | Corrigé en |
|---|---|---|
| 11.1 | >= 11.1.0, < 11.1.2-h3 | 11.1.2-h3 |
| 11.0 | >= 11.0.0, < 11.0.4-h1 | 11.0.4-h1 |
| 10.2 | >= 10.2.0, < 10.2.9-h1 | 10.2.9-h1 |
Selon l’éditeur, les versions non listées ne sont pas affectées.
Contournement / Remédiation de l’éditeur
Contournement · PAN-OS
Recommended Mitigation: Customers with a Threat Prevention subscription can block attacks for this vulnerability using Threat IDs 95187, 95189, and 95191 (available in Applications and Threats content version 8836-8695 and later). Please monitor this advisory and new Threat Prevention content updates for additional Threat Prevention IDs around CVE-2024-3400. To apply the Threat IDs, customers must ensure that vulnerability protection has been applied to their GlobalProtect interface to prevent exploitation of this issue on their device. Please see https://live.paloaltonetworks.com/t5/globalprotect-articles/applying-vulnerability-protection-to-globalprotect-interfaces/ta-p/340184 for more information.
Remédiation de l’éditeur · PAN-OS
We strongly advise customers to immediately upgrade to a fixed version of PAN-OS to protect their devices even when workarounds and mitigations have been applied. This issue is fixed in PAN-OS 10.2.9-h1, PAN-OS 11.0.4-h1, PAN-OS 11.1.2-h3, and in all later PAN-OS versions. Customers who upgrade to these versions will be fully protected.
Références
- https://security.paloaltonetworks.com/CVE-2024-3400(s’ouvre dans un nouvel onglet)
- https://unit42.paloaltonetworks.com/cve-2024-3400/(s’ouvre dans un nouvel onglet)
- https://www.volexity.com/blog/2024/04/12/zero-day-exploitation-of-unauthenticated-remote-code-execution-vulnerability-in-globalprotect-cve-2024-3400/(s’ouvre dans un nouvel onglet)
- https://www.paloaltonetworks.com/blog/2024/04/more-on-the-pan-os-cve/(s’ouvre dans un nouvel onglet)
- https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2024-3400(s’ouvre dans un nouvel onglet)
Provenance
Chaque information de cette page provient des sources ci-dessous. Rien n’est rédigé par une IA.
- Palo Alto Networks (CVE record)
- Palo Alto Networks (CVE record) · 27 sept. 2026, 23:46 UTC · Analyseur patcharo-cve5/1.1.0
- CISA Known Exploited Vulnerabilities
- CISA Known Exploited Vulnerabilities · 27 sept. 2026, 23:42 UTC · Analyseur patcharo-kev/1.0.0
- NVD
- NVD · 27 sept. 2026, 23:44 UTC · Analyseur patcharo-nvd/1.0.0
- FIRST EPSS
- FIRST EPSS · 27 sept. 2026, 23:46 UTC · Analyseur patcharo-epss/1.0.0
Dernière vérification : 28 sept. 2026, 02:31 UTC