Palo Alto Networks patched CVE-2024-3400, a command-injection vulnerability in the GlobalProtect feature of PAN-OS firewalls, on April 14, 2024. The company's advisory rates the flaw 10.0 out of 10 on CVSS, and states that exploitation of the vulnerability was observed on unpatched devices — with security firm WatchTowr reporting working exploitation within roughly 18 hours of the patch's release. If your organization runs PAN-OS with GlobalProtect enabled, patching and device checks come before anything else.
KAJ News publishes information, not incident response; organizations with signs of compromise should engage their incident-response process.
Fact block: CVE-2024-3400 · PAN-OS 10.2, 11.0, and 11.1 with GlobalProtect gateway or portal enabled · severity 10.0 CVSS as rated by Palo Alto Networks' April 14, 2024 advisory · exploitation confirmed by the vendor on unpatched and unmitigated devices · fix available in PAN-OS 10.2.9-h1, 11.0.4-h1, and 11.1.2-h3, with later hotfixes extending coverage to additional maintenance releases.
Who is affected?
Firewalls running PAN-OS versions 10.2, 11.0, or 11.1 with a GlobalProtect gateway or portal enabled — the remote-access VPN feature — are in scope per the vendor advisory. Firewalls without GlobalProtect enabled are not exposed to this specific flaw, and Panorama management interfaces are covered by a separate advisory line. The vulnerability allowed an unauthenticated attacker to run commands with root privileges on the firewall, per the advisory's technical description. The U.S. Cybersecurity and Infrastructure Security Agency added CVE-2024-3400 to its Known Exploited Vulnerabilities catalog on April 12, 2024, requiring federal agencies to remediate.
What should you do right now?
The vendor-confirmed path, in order per the April 14, 2024 advisory and its updates:
- Upgrade to the fixed release for your train: PAN-OS 10.2.9-h1, 11.0.4-h1, or 11.1.2-h3. This is the vendor-confirmed fix.
- If immediate patching is not possible, apply the documented workaround: enable the threat signature for command injection on the GlobalProtect interface and set it to reset both sides. This is a vendor-documented mitigation, not a fix — the advisory labels it temporary.
- Check for signs of exploitation using the vendor's indicators of compromise, which list specific file paths and utility names observed in attacks.
- If indicators are present, treat the device as compromised: collect telemetry, rotate credentials that transited the device, and engage incident response before trusting the box again.
What is confirmed: the flaw, the rating, the patches, and observed exploitation on unpatched devices. What is not established in the public record reviewed here: the identity of the attackers or the full set of victims — no attribution appears in the vendor advisory, and none is offered here.
For more context, read What is an MFA fatigue attack, and how do you stop it.
For more context, read aveo.
