
CVE-2024-3400 is an unauthenticated command injection in Palo Alto Networks PAN-OS GlobalProtect gateway feature. Attackers send crafted requests to trigger arbitrary commands as root on the firewall itself.
Affected configurations
- PAN-OS 10.2.x before 10.2.9-h1
- PAN-OS 11.0.x before 11.0.4-h1
- PAN-OS 11.1.x before 11.1.2-h3
- GlobalProtect gateway enabled on the device
Verify on appliance
show system info | match sw-version
show vpn global-protect-gatewayRemediation
- Apply Palo Alto hotfix from vendor advisory immediately
- Restrict GlobalProtect portal/gateway to trusted IPs if patch is delayed
- Inspect
/var/log/panfor suspicious GlobalProtect HTTP requests - Assume compromise if internet-facing and unpatched — rotate management credentials
Threat groups weaponized this within days; treat edge firewalls as crown jewels.