CVE-2024-3400 is a critical command injection vulnerability in the GlobalProtect feature of Palo Alto Networks PAN-OS software, allowing unauthenticated attackers to execute arbitrary code with root privileges on affected firewalls. This vulnerability specifically impacts certain PAN-OS versions and configurations, while Cloud NGFW, Panorama, and Prisma Access are not affected. With a CVSS score of 10.0, it presents a severe risk due to its network-based attack vector, low attack complexity, and complete compromise of confidentiality, integrity, and availability. The vulnerability is actively exploited in the wild, including in known ransomware campaigns, with publicly available exploit modules and significant community discussion and media coverage highlighting its widespread impact.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
10.2.0CPE matchmatch criteria | cpe:2.3:o:paloaltonetworks:pan-os:10.2.0:-:*:*:*:*:*:* | ||
10.2.0CPE matchmatch criteria | cpe:2.3:o:paloaltonetworks:pan-os:10.2.0:h1:*:*:*:*:*:* | ||
10.2.0CPE matchmatch criteria | cpe:2.3:o:paloaltonetworks:pan-os:10.2.0:h2:*:*:*:*:*:* | ||
10.2.1CPE matchmatch criteria | cpe:2.3:o:paloaltonetworks:pan-os:10.2.1:-:*:*:*:*:*:* | ||
10.2.1CPE matchmatch criteria | cpe:2.3:o:paloaltonetworks:pan-os:10.2.1:h1:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.3 Bluesky, 0.3 Mastodon, and 2.4 GitHub mentions.
The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.