Skip to main content

Palo Alto Releases Critical Security Update for PAN-OS GlobalProtect Gateway

Successful exploitation of CVE-2024-3400 could lead to remote code execution

Report a cyber attack: call 0300 303 5222 or email [email protected]

Summary

Successful exploitation of CVE-2024-3400 could lead to remote code execution


Threat details

Disabling device telemetry no longer an effective mitigation of CVE-2024-3400

Palo Alto Networks have updated their advisory to reflect that disabling device telemetry on PAN-OS is no longer an effective mitigation for this vulnerability. Affected organisations are encouraged to follow the other methods listed below to remediate CVE-2024-3400.


Introduction

Palo Alto has released a security update addressing a critical vulnerability in the GlobalProtect Gateway component of PAN-OS. GlobalProtect Gateway enforces security policies for web traffic and provides VPN functionality for Palo Alto firewalls.

The vulnerability CVE-2024-3400 is a command injection vulnerability with a CVSSv4 score of 10.0, which if exploited could allow a remote, unauthenticated attacker to execute arbitrary code with root privileges on the firewall.

Appliances are only vulnerable if they are running a vulnerable version of PAN-OS and are using the GlobalProtect Gateway functionality.

UPDATE 17/04/2024:

Previous versions of this cyber alert stated that device telemetry needed to be enabled for devices to be vulnerable to CVE-2024-3400. Device telemetry does not need to be enabled for PAN-OS firewalls to be exposed to attacks related to this vulnerability.

Exploitation and proof-of-concept for CVE-2024-3400

Palo Alto have confirmed that there are a limited number of attacks exploiting CVE-2024-3400 in the wild.

Firewall and VPN appliances are internet-facing by design and frequent targets for cyber threat groups. Vulnerabilities in firewall and VPN appliances are often exploited soon after official disclosure and broader exploitation is expected.

Proof-of-concept code has been publicly released for vulnerability CVE-2024-3400. Exploitation is more likely.


Threat updates

Date Update
18 Apr 2024 Updated mitigation for organisations with a Threat Prevention subscription

Organisations with a Threat Prevention subscription who temporarily mitigated CVE-2024-3400 by enabling Threat ID 95187 are strongly encouraged to additionally enable the new Threat IDs 95189 and 95191.

This cyber alert has been updated to reflect this change.

17 Apr 2024 Disabling device telemetry is no longer an effective mitigation of CVE-2024-3400

This cyber alert has been updated to reflect this change.

15 Apr 2024 Patches available for PAN-OS 10.2, 11.0, and 11.1

This cyber alert has been updated to reflect this change.


Remediation advice

Affected organisations are required to apply the relevant update to PAN-OS as soon as security patches are publicly released. Palo Alto have stated that they expect the patches to be released by April 14, 2024. This Cyber Alert will be updated to reflect this change when these patches are made available, and a threat update issued. UPDATE 15/04/2024: These patches have now been released. 

Until a patch is available, affected organisations are strongly encouraged to apply the relevant mitigations detailed in the Palo Alto Networks Security Advisory.

The required steps are detailed below.

NOTE: Responses to this High Severity Alert may only be marked "Complete" once the PAN-OS patches are applied.


Remediation steps

Type Step
Patch

The vulnerability will be fixed in hotfix releases of PAN-OS 10.2.9-h1, PAN-OS 11.0.4-h1, and PAN-OS 11.1.2-h3 – these patches are in development and are expected to be released by April 14, 2024.

Organisations are required to apply the relevant update as soon as these become publicly available.

 

UPDATE 15/04/2024:

Palo Alto have now updated their advisory following official release of security updates addressing CVE-2024-3400.

The vulnerability has been remediated in hotfix releases of PAN-OS 10.2.9-h1, PAN-OS 11.0.4-h1, PAN-OS 11.1.2-h3, and in all later PAN-OS versions. Organisations are required to implement these security updates as soon as possible.

Palo Alto has also advised that hotfixes are planned for many other commonly deployed maintenance releases of PAN-OS. Please review the Palo Alto Advisory for details.


https://security.paloaltonetworks.com/CVE-2024-3400
Guidance

Organisations with a Threat Prevention subscription may enable Threat IDs 95187, 95189, and 95191 to temporarily mitigate attacks exploiting this vulnerability. Additionally, organisations implementing this mitigation must ensure vulnerability protection has been applied to their GlobalProtect interface to prevent exploitation of CVE-2024-3400. Please see the guidance at the below link for full details.


https://security.paloaltonetworks.com/CVE-2024-3400
Guidance

UPDATE 17/04/2024:

In earlier versions of this cyber alert, disabling device telemetry was listed as a secondary mitigation action. Disabling device telemetry is no longer an effective mitigation. Device telemetry does not need to be enabled for PAN-OS firewalls to be exposed to attacks related to this vulnerability. Please see the guidance at the below link for full details.


https://security.paloaltonetworks.com/CVE-2024-3400

Definitive source of threat updates


Last edited: 18 April 2024 3:42 pm