CVE-2024-3400
Tracked as CVE-2024-3400 and rated with the maximum CVSS score of 10.0, this is a command injection vulnerability that could allow unauthorized cybercriminals to execute arbitrary code with root privileges on affected firewalls.
The specific PAN-OS versions affected by this issue are:
Exploitation Status
It's crucial to underscore that this vulnerability is only exploitable on firewalls with both GlobalProtect gateway and device telemetry configurations enabled.
Extent of the Attacks
Palo Alto has acknowledged exploitation of this flaw on a limited number of instances. However, no additional technical details about the nature of the attacks have been shared to date.
Remediation
In response to this threat, Palo Alto Networks advises customers with Threat Prevention subscriptions to activate Threat ID 95187 as a protective measure.
The company will release fixes for these versions on April 14, 2024.
Holm Security has developed a vulnerability test to check if a vulnerable version is present on the host: