LiveBreach Intelligence: data breaches, leaks & ransomware, tracked as they surfaceOngoing protection: GalaxyWarden →
Recent BreachesData breach tracker

CVE-2024-3400: Palo Alto Networks PAN-OS Command Injection Vulnerability

RBRecent Breaches Vulnerability Intelligence·Apr 12, 2024
Critical⚠ Actively exploited (CISA KEV)Ransomware-linked
Critical
Severity
Active
CISA KEV
Yes
Ransomware use
Apr 19, 2024
Patch deadline
⚠ Exploited in the wild. CISA added CVE-2024-3400 to its Known Exploited Vulnerabilities catalog on Apr 12, 2024, with a federal patch deadline of Apr 19, 2024 — meaning attackers are actively using it. If you run the affected software, patch it immediately. Ransomware crews are known to exploit this flaw.

Palo Alto Networks PAN-OS GlobalProtect feature contains a command injection vulnerability that allows an unauthenticated attacker to execute commands with root privileges on the firewall.

CVE-2024-3400 is a command injection vulnerability in the GlobalProtect feature of Palo Alto Networks PAN-OS. An unauthenticated attacker can exploit it to execute arbitrary commands with root privileges on the firewall itself.

This is significant because PAN-OS devices commonly serve as perimeter firewalls and VPN gateways. Full root-level control of such a device can expose internal networks, enable traffic interception or redirection, and has been observed in ransomware operations. Defenders should treat internet-facing GlobalProtect instances as high priority until confirmed patched or mitigated.

How it works

The vulnerability is classified under CWE-20 (Improper Input Validation) and CWE-77 (Command Injection). In the GlobalProtect feature, insufficient validation of attacker-supplied input allows commands to be injected and executed by the underlying operating system with root privileges. Because authentication is not required, any party that can reach the vulnerable GlobalProtect interface can attempt exploitation.

Exact request formats, injection points, or payload construction are not detailed here; those mechanics must be confirmed against the official Palo Alto Networks advisory. For this class of flaw, the practical risk is that a single crafted request can lead to arbitrary code execution on the firewall management plane, after which an attacker can install persistence, alter security policy, or pivot deeper into the environment.

Am I affected? How to find it in your systems

The issue affects Palo Alto Networks PAN-OS systems that use the GlobalProtect feature. These appliances typically operate as next-generation firewalls at network perimeters, in data centers, or as remote-access VPN gateways.

Telemetry signs of exploitation for this class of vulnerability include unexpected command execution on the firewall, anomalous GlobalProtect session or portal activity, sudden configuration changes, or outbound connections originating from the device itself. Specific detection signatures and log patterns should be obtained from the vendor and from CISA guidance.

How to remediate

The primary remediation is to apply the vendor software update that addresses CVE-2024-3400. Follow the patch release schedule and upgrade instructions published in the Palo Alto Networks security advisory for your specific PAN-OS release train.

CISA’s required action is to apply mitigations per vendor instructions as they become available. Where an immediate upgrade is not yet possible, enable the Threat Prevention IDs that Palo Alto Networks has released for this vulnerability. Confirm the exact signature identifiers and recommended policy settings directly from the vendor bulletin.

After patching, re-validate that GlobalProtect remains functional, re-apply any temporary hardening, and confirm that the device reports the fixed version.

If you can't patch immediately

Until the vendor update can be installed, reduce exposure with the following compensating controls:

These steps do not eliminate the vulnerability; they only lower the likelihood and impact of successful exploitation until the official update is deployed.

If your data may have been exposed

Because CVE-2024-3400 is known to have been used in ransomware campaigns, any internet-exposed, unpatched GlobalProtect instance should be treated as potentially compromised. Conduct a full forensic review of the device, look for indicators of compromise supplied by the vendor and CISA, rotate credentials that the firewall could have accessed, and examine internal network traffic for signs of follow-on activity.

You can also run a free exposure scan of your organization’s email addresses against known breach datasets to determine whether related credentials or personal data have already appeared in public dumps.

AICompiled with AI assistance from public sources and published under our editorial standards.

Details

AffectedPalo Alto Networks · PAN-OS
WeaknessCWE-20
Added to CISA KEVApr 12, 2024
Federal patch deadlineApr 19, 2024
Known ransomware useYes
Check if your data is exposed →

Official records: NVD · CISA KEV

← All actively-exploited vulnerabilities