← Back

CVE-2024-3400

Published: Apr 12, 2024Modified: Nov 4, 2025CISA KEV

JSON object

Loading...
10.0
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H
Exploitability: 3.9 / Impact: 6.0
Source: NVD

Description

A command injection as a result of arbitrary file creation vulnerability in the GlobalProtect feature of Palo Alto Networks PAN-OS software for specific PAN-OS versions and distinct feature configurations may enable an unauthenticated attacker to execute arbitrary code with root privileges on the firewall. Cloud NGFW, Panorama appliances, and Prisma Access are not impacted by this vulnerability.

Affected (52)

Pan Os
Configuration A
52 vulnerable
Vulnerable SoftwareAffected Versions
Paloaltonetworks
Version 10.2.0
Version 10.2.0 h1
Version 10.2.0 h2
Version 10.2.1
Version 10.2.1 h1
Version 10.2.2
Version 10.2.2 h1
Version 10.2.2 h2
Version 10.2.2 h4
Version 10.2.3
Version 10.2.3 h11
Version 10.2.3 h12
Version 10.2.3 h2
Version 10.2.3 h4
Version 10.2.3 h9
Version 10.2.4
Version 10.2.4 h10
Version 10.2.4 h2
Version 10.2.4 h3
Version 10.2.4 h4
Version 10.2.5
Version 10.2.5 h1
Version 10.2.5 h4
Version 10.2.6
Version 10.2.6 h1
Version 10.2.7
Version 10.2.7 h1
Version 10.2.7 h3
Version 10.2.7 h6
Version 10.2.8
Version 10.2.9
Version 11.0.0
Version 11.0.0 h1
Version 11.0.0 h2
Version 11.0.1
Version 11.0.1 h2
Version 11.0.1 h3
Version 11.0.2
Version 11.0.2 h1
Version 11.0.2 h2
Version 11.0.2 h3
Version 11.0.3
Version 11.0.3 h1
Version 11.0.3 h3
Version 11.0.3 h5
Version 11.0.4
Version 11.1.0
Version 11.1.0 h1
Version 11.1.0 h2
Version 11.1.1
Version 11.1.2
Version 11.1.2 h1

References (9)

Source: psirt@paloaltonetworks.com
Vendor Advisory
Source: psirt@paloaltonetworks.com
ExploitVendor Advisory
Source: psirt@paloaltonetworks.com
Technical DescriptionVendor Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Vendor Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
ExploitVendor Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Technical DescriptionVendor Advisory
Source: 134c704f-9b21-4f2e-91b3-4a467353bcc0
US Government Resource

Timeline

No history available yet.