LOWVulnerability

CVE-2024-3400

Palo Alto Networks PAN-OS GlobalProtect feature contains a command injection vulnerability that allows an unauthenticated attacker to execute commands with root privileges on the firewall.

Properties

product
PAN-OS
vulnerabilityName
Palo Alto Networks PAN-OS Command Injection Vulnerability
epss_score
0.99999
cve_id
CVE-2024-3400
dueDate
2024-04-19
vendorProject
Palo Alto Networks
requiredAction
Apply mitigations per vendor instructions as they become available. Otherwise, users with vulnerable versions of affected devices should enable Threat Prevention IDs available from the vendor. See the vendor bulletin for more details and a patch release schedule.
dateAdded
2024-04-12
epss_percentile
1

Related Entities (9)

MENTIONED_IN (5)

[Campaign]A Deep Dive Into Attempted Exploitation of CVE-2023-33538
[Campaign]NightLedger Backdoor Deployed in Espionage Campaign Targeting the Middle East and Africa
[Campaign]ClickFix-Themed Campaign Deploys Starland RAT and WLDR Framework
[Campaign]699733d20abc04f566f5d380
[Campaign]2025 Cloud Threat Hunting and Defense Landscape

KNOWN_EXPLOITED (1)

[Source]CISA KEV

INVOLVES (1)

[EmergentSignal]

ENRICHED_BY (1)

[Source]FIRST EPSS

DESCRIBES (1)

[KEVEntry]Palo Alto Networks PAN-OS Command Injection Vulnerability

Explore deeper with Ninja Signal's threat intelligence graph

CVE-2024-3400 — Ninja Signal Threat Intelligence | Ninja Signal