Hack The Sec - Leading Resource Of Linux Tutorial
Palo Alto PAN-OS GlobalProtect Command Injection (CVE-2024-3400)

Palo Alto PAN-OS GlobalProtect Command Injection (CVE-2024-3400)

PAN-OS GlobalProtect version check for CVE-2024-3400

CVE-2024-3400 is an unauthenticated command injection in Palo Alto Networks PAN-OS GlobalProtect gateway feature. Attackers send crafted requests to trigger arbitrary commands as root on the firewall itself.

Affected configurations

  • PAN-OS 10.2.x before 10.2.9-h1
  • PAN-OS 11.0.x before 11.0.4-h1
  • PAN-OS 11.1.x before 11.1.2-h3
  • GlobalProtect gateway enabled on the device

Verify on appliance

show system info | match sw-version
show vpn global-protect-gateway

Remediation

  • Apply Palo Alto hotfix from vendor advisory immediately
  • Restrict GlobalProtect portal/gateway to trusted IPs if patch is delayed
  • Inspect /var/log/pan for suspicious GlobalProtect HTTP requests
  • Assume compromise if internet-facing and unpatched — rotate management credentials

Threat groups weaponized this within days; treat edge firewalls as crown jewels.

H

About the author

I am a Linux Administrator and Security Expert. Through this site I share Linux tutorials, hardening guides and security news.

Comments