CVE-2024-3400
PAN-OS GlobalProtect command injection
Unauthenticated command injection in GlobalProtect on specific PAN-OS releases. CISA KEV lists it, with known ransomware use, and the vendor reported exploitation before a fix existed.
- CVSS
- 10
- Vector
- CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H
- Class
- RCE
- Status
- Active Exploitation
- KEV
- Listed in CISA KEV
- 0-day
- Yes
- Vendor
- Palo Alto Networks
- Products
- PAN-OS
- Affected
- PAN-OS 10.2 before 10.2.9-h1, PAN-OS 11.0 before 11.0.4-h1, and PAN-OS 11.1 before 11.1.2-h3, when GlobalProtect gateway or portal is configured. Cloud NGFW, Panorama, and Prisma Access are not affected.
- Fixed
- PAN-OS 10.2.9-h1, 11.0.4-h1, 11.1.2-h3, and later versions. The vendor advisory also lists courtesy hotfixes for other maintenance releases.
- CWE
- CWE-77
- Published
- 12 Apr 2024
- Updated
- 5 Oct 2026
The status above is the claim. Links do not upgrade it.
CVE-2024-3400 is a command injection in the GlobalProtect feature of Palo Alto Networks PAN-OS. An unauthenticated attacker can create files in a way that leads to command execution as root on an affected firewall.
NVD scores it 10.0. The vendor says the issue applies to PAN-OS 10.2, 11.0, and 11.1 firewalls with a GlobalProtect gateway or portal configured. Cloud NGFW, Panorama appliances, and Prisma Access are not affected.
CISA added the vulnerability to the Known Exploited Vulnerabilities catalog on 12 April 2024. The catalog entry notes known ransomware use. The vendor reported in-the-wild exploitation before fixed builds were available, so this record is marked both 0-day and Active Exploitation.
The first complete fixes called out by the vendor are PAN-OS 10.2.9-h1, 11.0.4-h1, and 11.1.2-h3, plus later versions and the hotfixes listed in the advisory. ThreatWire does not republish exploit code or the vendor's validation command. Use the advisory for patch detail.