Skip to content
THREATWIRE

CVE

CriticalActive ExploitationKEV0-day

CVE-2024-3400

PAN-OS GlobalProtect command injection

Unauthenticated command injection in GlobalProtect on specific PAN-OS releases. CISA KEV lists it, with known ransomware use, and the vendor reported exploitation before a fix existed.

CVSS
10
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H
Class
RCE
Status
Active Exploitation
KEV
Listed in CISA KEV
0-day
Yes
Vendor
Palo Alto Networks
Products
PAN-OS
Affected
PAN-OS 10.2 before 10.2.9-h1, PAN-OS 11.0 before 11.0.4-h1, and PAN-OS 11.1 before 11.1.2-h3, when GlobalProtect gateway or portal is configured. Cloud NGFW, Panorama, and Prisma Access are not affected.
Fixed
PAN-OS 10.2.9-h1, 11.0.4-h1, 11.1.2-h3, and later versions. The vendor advisory also lists courtesy hotfixes for other maintenance releases.
Published
12 Apr 2024
Updated
5 Oct 2026

The status above is the claim. Links do not upgrade it.

CVE-2024-3400 is a command injection in the GlobalProtect feature of Palo Alto Networks PAN-OS. An unauthenticated attacker can create files in a way that leads to command execution as root on an affected firewall.

NVD scores it 10.0. The vendor says the issue applies to PAN-OS 10.2, 11.0, and 11.1 firewalls with a GlobalProtect gateway or portal configured. Cloud NGFW, Panorama appliances, and Prisma Access are not affected.

CISA added the vulnerability to the Known Exploited Vulnerabilities catalog on 12 April 2024. The catalog entry notes known ransomware use. The vendor reported in-the-wild exploitation before fixed builds were available, so this record is marked both 0-day and Active Exploitation.

The first complete fixes called out by the vendor are PAN-OS 10.2.9-h1, 11.0.4-h1, and 11.1.2-h3, plus later versions and the hotfixes listed in the advisory. ThreatWire does not republish exploit code or the vendor's validation command. Use the advisory for patch detail.

Sources

Related writing

Share on X@threatwire_https://www.threatwire.tech/cve/cve-2024-3400