CVE-2024-3400

PAN-OS: Arbitrary File Creation Leads to OS Command Injection Vulnerability in GlobalProtect

Severity
Critical 10
CVSS 3.1
Exploited
Yes — in CISA KEV
Added Apr 12, 2024 · known ransomware use
EPSS
1.000
100.0th percentile
Discovered by
Customer
Published by the vendor
Published
Apr 12, 2024
Assigned by palo_alto

Description

A command injection as a result of arbitrary file creation vulnerability in the GlobalProtect feature of Palo Alto Networks PAN-OS software for specific PAN-OS versions and distinct feature configurations may enable an unauthenticated attacker to execute arbitrary code with root privileges on the firewall. Cloud NGFW, Panorama appliances, and Prisma Access are not impacted by this vulnerability.

Weakness: CWE-20CWE-77

Affected products

Vendor Product Category Matched by
Palo Alto Networks Cloud NGFW Firewall / NGFW cna-assigner
Palo Alto Networks PAN-OS Firewall / NGFW cna-assigner
Palo Alto Networks Prisma Access SASE / SSE / Secure Web cna-assigner
Vendor-reported affected versions (6)
  • Palo Alto Networks · PAN-OS
  • Palo Alto Networks · Cloud NGFW
  • Palo Alto Networks · Prisma Access
  • paloaltonetworks · pan-os
  • paloaltonetworks · pan-os
  • paloaltonetworks · pan-os

Credit

Palo Alto Networks thanks Volexity for detecting and identifying this issue.

Vendor remediation

We strongly advise customers to immediately upgrade to a fixed version of PAN-OS to protect their devices even when workarounds and mitigations have been applied. This issue is fixed in PAN-OS 10.2.9-h1, PAN-OS 11.0.4-h1, PAN-OS 11.1.2-h3, and in all later PAN-OS versions. Customers who upgrade to these versions will be fully protected.