Security Advisory

PAN-OS GlobalProtect - Palo Alto Command Injection Vulnerability Advisory

A critical vulnerability (CVE-2024-3400) is being exploited and may enable an unauthenticated attacker to execute arbitrary code with root privileges on affected Palo Alto Networks PAN-OS products using GlobalProtect Gateway.

TLP:CLEAR Critical Businesses IT Practitioners 23 Apr 2024

A critical vulnerability (CVE-2024-3400) is being exploited and may enable an unauthenticated attacker to execute arbitrary code with root privileges on affected Palo Alto Networks PAN-OS products using GlobalProtect Gateway.

Advisory Details

A critical vulnerability (CVE-2024-3400) is being exploited and may enable an unauthenticated attacker to execute arbitrary code with root privileges on affected Palo Alto Networks PAN-OS products using GlobalProtect Gateway.

This is an older SamCERT firewall advisory migrated from the Firewall page. Download the attached PDF for the original advisory.

Trusted Partners & International Network: