PT-2024-2752 · Palo Alto Networks · Pan-Os

·

CVE-2024-3400

·

Published

2024-04-12

·

Updated

2026-08-26

CVSS v3.1

10

Critical

VectorAV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Palo Alto Networks PAN-OS versions 10.2 through 11.1
Description A command injection issue exists in the GlobalProtect feature of Palo Alto Networks PAN-OS software. The flaw allows an unauthenticated remote attacker to execute arbitrary code with root privileges on the firewall by creating an arbitrary file. This is achieved through a path traversal vulnerability in the SESSID cookie value, which allows writing to the /opt/panlogs/tmp/device telemetry/ directory. Subsequently, a command injection occurs within the pansys.py library when it uses the subprocess.Popen() function to send telemetry data via cron. The vulnerability is exploitable when the GlobalProtect feature and device telemetry are enabled. It has been estimated that between 40,000 and 133,000 devices worldwide may be affected. Real-world exploitation has been observed in targeted attacks by the UTA0218 group (Operation MidnightEclipse) and the Black Shrantac ransomware group, involving the deployment of Python-based backdoors, credential harvesting, and lateral movement within networks.
Recommendations Update PAN-OS versions 10.2, 11.0, and 11.1 to the latest patched versions. As a temporary mitigation, disable the GlobalProtect feature or device telemetry to prevent exploitation.

Exploit

Fix

RCE

DoS

Command Injection

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

BDU:2024-02881
CVE-2024-3400
GO-2024-2730

Affected Products

Pan-Os