ZeroHour
Infosecurity Magazinepublished ()ingested Kevin Poireault

Palo Alto Networks Warns About Critical Zero-Day in PAN

criticalExploit / PoC exploited in the wildimportance 60CVE-2024-3400

Vulnerabilities mentionedAll →

CVEVulnerabilityCVSSEPSSFlagsAffectedExposurePublished
CVE-2024-3400
Unauthenticated Root Command Injection in Palo Alto Networks PAN-OS GlobalProtect

Palo Alto Networks PAN-OS contains a command injection flaw (CWE-77, with improper input validation per CWE-20) in its GlobalProtect feature, allowing an unauthenticated attacker to execute arbitrary operating-system commands with root privileges on the affected firewall. The flaw is triggered through the GlobalProtect interface, which in most deployments is reachable from untrusted networks, so no valid user credentials or prior access are required. Successful exploitation yields full root control of the firewall, the most powerful position in a network perimeter, enabling traffic interception, configuration tampering, and use as a foothold for further compromise. All PAN-OS firewalls running affected releases with the GlobalProtect feature are exposed; CISA added the issue to the KEV catalog on 2024-04-12 with ransomware use noted, and EPSS puts the 30-day exploitation probability at 100% (100th percentile). No public proof-of-concept is recorded in the source data, but confirmed in-the-wild exploitation makes patching urgent.

Do: Apply the PAN-OS patches released in Palo Alto Networks' bulletin according to its published patch schedule, prioritizing internet-facing firewalls. Until patched, enable the vendor's Threat Prevention signatures as required by CISA KEV, restrict exposure of the GlobalProtect interface to trusted sources where possible, and review logs and device configuration for signs of compromise given confirmed exploitation with known ransomware use.

10.0100% KEV ransomware PoC ×2
  • Palo Alto Networks PAN-OS
large≈10,000–100,000 internet-exposed PAN-OS firewalls with GlobalProtect enabled
Full article332 words · extracted from infosecurity-magazine.com · click to collapse

A critical zero-day vulnerability in Palo Alto Networks’ PAN-OS software, used in its GlobalProtect gateways, is being exploited in the wild, and no patches are available yet.

Palo Alto Networks issued an alert about the flaw on April 12, 2024, thanking cybersecurity firm Volexity for discovering it.

The vulnerability is a command injection vulnerability in the GlobalProtect feature of Palo Alto Networks’ PAN-OS software for specific PAN-OS versions.

The zero-day has been registered as CVE-2024-3400 and attributed the highest severity score (CVSS of 10.0).

“Distinct feature configurations may enable an unauthenticated attacker to execute arbitrary code with root privileges on the firewall," Palo Alto said in the advisory.

Limited Active Exploitation

The versions concerned are the following:

  • PAN-OS < 11.1.2-h3
  • PAN-OS < 11.0.4-h1
  • PAN-OS < 10.2.9-h1

The company also said that the vulnerability can only be exploited with firewalls that have the configurations for both GlobalProtect gateway (Network > GlobalProtect > Gateways) and device telemetry (Device > Setup > Telemetry) enabled.

The firm is aware of a limited number of attacks that leverage the exploitation of this vulnerability.

Upcoming Fixes for CVE-2024-3400

Although there are no fixes available, Palo Alto issued some mitigation recommendations:

  • Apply a vulnerability protection security profile to the GlobalProtect interface to prevent exploitation
  • Customers with a Threat Prevention subscription can block attacks for this vulnerability by enabling Threat ID 95187

The firm announced the flaw will be fixed on April 14 during a series of hotfixes for PAN-OS versions 11.1.2-h3, 11.0.4-h1, and 10.2.9-h1.

CVE 2024-3385, Another (Fixed) Flaw in PAN-OS

This advisory comes two days after another vulnerability was discovered in PAN-OS.

Registered as CVE 2024-3385, the high-severity flaw was spotted in a Palo Alto Networks PAN-OS software packet processing mechanism included in PA-5400 and PA-7000 Series firewalls. It enables a remote attacker to reboot hardware-based firewalls and can lead to a denial of service (DoS) attack.

This issue was fixed in PAN-OS 9.0.17-h4, PAN-OS 9.1.17, PAN-OS 10.1.12, PAN-OS 10.2.8, PAN-OS 11.0.3, and all later PAN-OS versions.

Text extracted automatically; images, tables and formatting may be missing. Original: https://www.infosecurity-magazine.com/news/palo-alto-critical-zero-day/