logo
Home/CVEs/CVE-2024-3400/

CVE-2024-3400 - Palo Alto Networks PAN-OS Command Injection Vulnerability

Project:Palo Alto Networks

Product:PAN-OS

Date Added:2024-04-12Due Date:2024-04-19

Vulnerability Name

Palo Alto Networks PAN-OS Command Injection Vulnerability

Description

Palo Alto Networks PAN-OS GlobalProtect feature contains a command injection vulnerability that allows an unauthenticated attacker to execute commands with root privileges on the firewall.

Known To Be Used in Ransomware Campaigns?

Known

Action

Apply mitigations per vendor instructions as they become available. Otherwise, users with vulnerable versions of affected devices should enable Threat Prevention IDs available from the vendor. See the vendor bulletin for more details and a patch release schedule.

Additional Notes

https://security.paloaltonetworks.com/CVE-2024-3400

https://nvd.nist.gov/vuln/detail/CVE-2024-3400

Related News Articles

Salt Typhoon Exploits Flaws in Edge Network Devices to Breach 600 Organizations WorldwideAugust 28, 2025

Salt Typhoon Exploits Cisco, Ivanti, Palo Alto Flaws to Breach 600 Organizations WorldwideAugust 28, 2025

Global Salt Typhoon hacking campaigns linked to Chinese tech firmsAugust 28, 2025

Chinese hackers breached National Guard to steal network configurationsJuly 18, 2025

Chinese Hackers Target Taiwan's Semiconductor Sector with Cobalt Strike, Custom BackdoorsJuly 17, 2025