Aller au contenu
Toutes les vulnérabilités
CVE-2024-3400KEVRançongiciel

PAN-OS: Arbitrary File Creation Leads to OS Command Injection Vulnerability in GlobalProtect

Sévérité
Critique10CVSS 3.1, Critique
EPSS
100 %
Publiée
12 avr. 2024
Mise à jour
17 juin 2026

Description

Le titre, la description et les consignes de l’éditeur sont cités depuis les enregistrements sources (en anglais).

A command injection as a result of arbitrary file creation vulnerability in the GlobalProtect feature of Palo Alto Networks PAN-OS software for specific PAN-OS versions and distinct feature configurations may enable an unauthenticated attacker to execute arbitrary code with root privileges on the firewall. Cloud NGFW, Panorama appliances, and Prisma Access are not impacted by this vulnerability.

Faiblesse : CWE-77, CWE-20

Exploitée activement

Ajoutée au catalogue CISA KEV le 12 avr. 2024

Date limite de remédiation fédérale : 19 avr. 2024

Utilisation connue par des rançongiciels

Action requise : Apply mitigations per vendor instructions as they become available. Otherwise, users with vulnerable versions of affected devices should enable Threat Prevention IDs available from the vendor. See the vendor bulletin for more details and a patch release schedule.

Prédiction d’exploitation

Probabilité d’exploitation de 100 % dans les 30 prochains jours (percentile 100 %).

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H

Ce qu’indique la source, par branche

Versions comparées par Patcharo

Palo Alto Networks PAN-OSSource : Palo Alto Networks (CVE record)

BrancheAffectéesCorrigé en
11.1
>= 11.1.0, < 11.1.2-h3
11.1.2-h3
11.0
>= 11.0.0, < 11.0.4-h1
11.0.4-h1
10.2
>= 10.2.0, < 10.2.9-h1
10.2.9-h1

Selon l’éditeur, les versions non listées ne sont pas affectées.

Contournement / Remédiation de l’éditeur

Contournement · PAN-OS

Recommended Mitigation: Customers with a Threat Prevention subscription can block attacks for this vulnerability using Threat IDs 95187, 95189, and 95191 (available in Applications and Threats content version 8836-8695 and later). Please monitor this advisory and new Threat Prevention content updates for additional Threat Prevention IDs around CVE-2024-3400. To apply the Threat IDs, customers must ensure that vulnerability protection has been applied to their GlobalProtect interface to prevent exploitation of this issue on their device. Please see https://live.paloaltonetworks.com/t5/globalprotect-articles/applying-vulnerability-protection-to-globalprotect-interfaces/ta-p/340184 for more information.

Remédiation de l’éditeur · PAN-OS

We strongly advise customers to immediately upgrade to a fixed version of PAN-OS to protect their devices even when workarounds and mitigations have been applied. This issue is fixed in PAN-OS 10.2.9-h1, PAN-OS 11.0.4-h1, PAN-OS 11.1.2-h3, and in all later PAN-OS versions. Customers who upgrade to these versions will be fully protected.

Références

Provenance

Chaque information de cette page provient des sources ci-dessous. Rien n’est rédigé par une IA.

Palo Alto Networks (CVE record)
Palo Alto Networks (CVE record) · 27 sept. 2026, 23:46 UTC · Analyseur patcharo-cve5/1.1.0
CISA Known Exploited Vulnerabilities
CISA Known Exploited Vulnerabilities · 27 sept. 2026, 23:42 UTC · Analyseur patcharo-kev/1.0.0
NVD
NVD · 27 sept. 2026, 23:44 UTC · Analyseur patcharo-nvd/1.0.0
FIRST EPSS
FIRST EPSS · 27 sept. 2026, 23:46 UTC · Analyseur patcharo-epss/1.0.0

Dernière vérification : 28 sept. 2026, 02:31 UTC