Palo Alto firewalls: CVE-2024-3400 exploitation and PoCs for persistence after resets/upgrades
Vulnerabilities mentionedAll →
| CVE | Vulnerability | CVSS | EPSS | Flags | Affected | Exposure | Published |
|---|---|---|---|---|---|---|---|
| CVE-2024-3400 | Unauthenticated Root Command Injection in Palo Alto Networks PAN-OS GlobalProtect Palo Alto Networks PAN-OS contains a command injection flaw (CWE-77, with improper input validation per CWE-20) in its GlobalProtect feature, allowing an unauthenticated attacker to execute arbitrary operating-system commands with root privileges on the affected firewall. The flaw is triggered through the GlobalProtect interface, which in most deployments is reachable from untrusted networks, so no valid user credentials or prior access are required. Successful exploitation yields full root control of the firewall, the most powerful position in a network perimeter, enabling traffic interception, configuration tampering, and use as a foothold for further compromise. All PAN-OS firewalls running affected releases with the GlobalProtect feature are exposed; CISA added the issue to the KEV catalog on 2024-04-12 with ransomware use noted, and EPSS puts the 30-day exploitation probability at 100% (100th percentile). No public proof-of-concept is recorded in the source data, but confirmed in-the-wild exploitation makes patching urgent. Do: Apply the PAN-OS patches released in Palo Alto Networks' bulletin according to its published patch schedule, prioritizing internet-facing firewalls. Until patched, enable the vendor's Threat Prevention signatures as required by CISA KEV, restrict exposure of the GlobalProtect interface to trusted sources where possible, and review logs and device configuration for signs of compromise given confirmed exploitation with known ransomware use. | 10.0 | 100% | KEV ransomware PoC ×2 |
| large≈10,000–100,000 internet-exposed PAN-OS firewalls with GlobalProtect enabled |
Full article573 words · extracted from helpnetsecurity.com · click to collapse
There are proof-of-concept techniques allowing attackers to achieve persistence on Palo Alto Networks firewalls after CVE-2024-3400 has been exploited, the company has confirmed on Monday, but they are “not aware at this time of any malicious attempts to use these persistence techniques in active exploitation of the vulnerability.”
“These techniques work on a device that is already compromised with interactive root level command execution,” they added.

The evolving situation
On April 12, Palo Alto Networks warned about limited attacks against internet-exposed firewalls, likely by a state-backed threat actor, who managed to install backdoors, grab sensitive data, and move laterally through target organizations’ networks.
It was initially thought that the attackers exploited one zero-day vulnerability, but it was later confirmed by Rapid7 that they chained together two separate vulnerabilities: “an arbitrary file creation vulnerability in the GlobalProtect web server, for which no discrete CVE has been assigned, and a command injection vulnerability in the device telemetry feature, designated as CVE-2024-3400”.
Since then, Palo Alto Networks has been updating the associated security advisory and Unit 42 Threat Brief, as well as published additional advice for mitigation and remediation.
Fixes have been made available and customers have been advised to implement them even if they implemented mitigations (i.e., the Threat Prevention updates).
On April 18, the company said that “an increasing number of attacks that leverage the exploitation of this vulnerability” have been spotted and proof of concepts for the flaw(s) have been publicly disclosed by third parties.
On April 20, they confirmed that a tech support file (TSF) should be obtained “before rebooting into a fixed version of PAN-OS” because “some logs from the prior system installation will become inaccessible on the device.” Customers were advised to send the TSF to check whether their device logs match known attempted exploits for the vulnerability.
On April 23, Unit 42 said that the vast majority of cases they responded to have either been unsuccessful attempts to exploit the vulnerability or instances of the vulnerability being tested on the device. Other cases have included “limited” configuration file exfiltration and “very limited” interactive access compromises of the targeted firewalls.
Post-exploitation persistence on Palo Alto firewalls
On April 25, Palo Alto published remediation recommendations for customers (for each level of compromise), and on April 29 they confimed that they are aware of “proof-of-concept by third parties [i.e., Nick Wilson] of post-exploit persistence techniques that survive resets and upgrades.”
There is currently no indication that these techniques are being used by the initial or other attackers. Still, state-sponsored threat actors have previously found ways to install malware that survives reboots and firmware upgrades into Ivanti VPN appliances and have apparently managed to compromise Barracuda Networks’ phyisical Email Security Gateway (ESG) appliances in a way that makes their replacement imperative.
UPDATE (May 6, 2024, 04:10 a.m. ET):
Palo Alto now advises customers to open a case through Customer Support (TAC) if they want to schedule an enhanced factory reset (EFR) procedure that does not rely on the integrity of a potentially compromised device.
“This is recommended for customers who have not applied the PAN-OS fixes or Threat Prevention signatures with vulnerability protection applied to the GlobalProtect interface (regardless of level of compromise) on or before April 25, 2024; or customers who are concerned about a persistent risk.”

Subscribe to our breaking news e-mail alert to never miss out on the latest breaches, vulnerabilities and cybersecurity threats. Subscribe here!

Text extracted automatically; images, tables and formatting may be missing. Original: https://www.helpnetsecurity.com/2024/04/30/palo-alto-firewalls-persistence-cve-2024-3400-exploitation/