PT-2024-2752 · Palo Alto Networks · Pan-Os
CVSS v3.1
10
Critical
| Vector | AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
Palo Alto Networks PAN-OS versions 10.2 through 11.1
Description
A command injection issue exists in the GlobalProtect feature of Palo Alto Networks PAN-OS software. The flaw allows an unauthenticated remote attacker to execute arbitrary code with root privileges on the firewall by creating an arbitrary file. This is achieved through a path traversal vulnerability in the
SESSID cookie value, which allows writing to the /opt/panlogs/tmp/device telemetry/ directory. Subsequently, a command injection occurs within the pansys.py library when it uses the subprocess.Popen() function to send telemetry data via cron. The vulnerability is exploitable when the GlobalProtect feature and device telemetry are enabled. It has been estimated that between 40,000 and 133,000 devices worldwide may be affected. Real-world exploitation has been observed in targeted attacks by the UTA0218 group (Operation MidnightEclipse) and the Black Shrantac ransomware group, involving the deployment of Python-based backdoors, credential harvesting, and lateral movement within networks.Recommendations
Update PAN-OS versions 10.2, 11.0, and 11.1 to the latest patched versions.
As a temporary mitigation, disable the GlobalProtect feature or device telemetry to prevent exploitation.
Exploit
Fix
RCE
DoS
Command Injection
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Pan-Os