Command injection in Palo Alto Networks PAN-OS GlobalProtect enables root code execution

What is CVE-2024-3400?

CVE-2024-3400 is a vulnerability classified as Improper Neutralization of Special Elements used in a Command ('Command Injection') and Improper Input Validation, affecting PAN-OS. This vulnerability is rated Critical, with a CVSS score of 10. This vulnerability has been observed being exploited in the wild.

Verify to continue the analysis

A short verification protects the vulnerability source and prevents automated AI abuse.

Overview

Original source data

A command injection as a result of arbitrary file creation vulnerability in the GlobalProtect feature of Palo Alto Networks PAN-OS software for specific PAN-OS versions and distinct feature configurations may enable an unauthenticated attacker to execute arbitrary code with root privileges on the firewall. Cloud NGFW, Panorama appliances, and Prisma Access are not impacted by this vulnerability.

Affected products and scope

The confirmed affected scope is PAN-OS firewalls configured with a GlobalProtect gateway, GlobalProtect portal, or both:

  • PAN-OS 10.2, starting at 10.2.0 and less than 10.2.9-h1, is affected. The primary fixed release is 10.2.9-h1; additional hotfixes for other maintenance releases are listed in Remediation.
  • PAN-OS 11.0, starting at 11.0.0 and less than 11.0.4-h1, is affected. The primary fixed release is 11.0.4-h1.
  • PAN-OS 11.1, starting at 11.1.0 and less than 11.1.2-h3, is affected. The primary fixed release is 11.1.2-h3.
  • Cloud NGFW managed services, Panorama appliances, and Prisma Access are identified as not impacted. Customer-managed VM-Series deployments in the cloud can still be affected when the relevant PAN-OS versions and GlobalProtect configurations are used.
  • The Palo Alto Networks advisory lists PAN-OS 10.1, 10.0, and 9.1 as unaffected. Deployments or branches not confirmed by the evidence in this entry should not be treated as safe merely because they are absent from the affected list.

Technical details

The flaw is in the GlobalProtect feature of PAN-OS and combines arbitrary file creation with operating system command injection. Palo Alto Networks states that session IDs were not sufficiently validated before being stored, while the code that enabled command injection was rewritten using defensive programming techniques in the fix. Attacker-controlled data can enter the GlobalProtect processing path on a firewall configured as a GlobalProtect gateway or portal and lead to command execution without authentication. The confirmed result is arbitrary code execution with root privileges on the firewall, which can enable shell access, tool downloads, or access to firewall configuration data. The complete request format and internal call chain are not established by the public evidence reviewed for this entry.

Exploitability

The vulnerability is remotely reachable over the network through a GlobalProtect gateway or portal, requires no authentication or user interaction, and is assessed in the normalized record as low complexity. It has been exploited in the wild, and third-party proof of concept code has been publicly disclosed. Unit 42 tracks the initial activity as Operation MidnightEclipse, while Volexity attributes the observed activity to the actor it calls UTA0218. Investigations recorded exploitability testing through zero-byte file creation, as well as compromises involving reverse shells, tool downloads, firewall configuration collection, and lateral movement into victim networks. Palo Alto Networks and Unit 42 stated at the time of their updates that they were not aware of malicious use of post-exploitation persistence techniques that survive resets and upgrades, although third-party proof of concept code for those techniques existed.

Technical impact

A remote attacker can achieve arbitrary code execution with root privileges on the firewall without an account or user interaction. That access can permit configuration disclosure or modification, persistence, tool deployment, operating system commands, and use of the firewall as a pivot into the internal network.

  • Technical consequences include loss of confidentiality, integrity, and availability for the firewall and data reachable through it.
  • The impact can extend to other systems if the attacker uses configuration data or credentials to move laterally.
  • Volexity observed configuration collection and access to internal resources during investigated compromises.
  • The actual impact on an individual device depends on whether exploitation succeeded, what data was available on the firewall, and whether the attacker continued activity after initial code execution.

Business impact

If exploited, an internet-facing firewall can be taken over with root privileges and used as an entry point to systems behind it. Investigated incidents included firewall configuration theft, tool downloads, reverse shell activity, and lateral movement.

  • Configuration data, credentials, secrets, or other sensitive information stored on the firewall may be exposed.
  • An attacker may use the compromised firewall to reach internal systems, increasing the incident scope beyond the original VPN device.
  • Because the firewall is an edge control point, response may require device isolation, forensic collection, credential and secret changes, and coordination with Palo Alto Networks.
  • A patch or prevention signature addresses the initial attack path but does not by itself remediate a device that was already compromised.

Remediation

  1. Upgrade immediately to a fixed PAN-OS release. The confirmed primary fixes are PAN-OS 10.2.9-h1, PAN-OS 11.0.4-h1, and PAN-OS 11.1.2-h3. The Palo Alto Networks advisory also states that all later PAN-OS versions are fixed. Additional hotfixes for commonly deployed maintenance releases include:
  • PAN-OS 10.2: 10.2.9-h1, 10.2.8-h3, 10.2.7-h8, 10.2.6-h3, 10.2.5-h6, 10.2.4-h16, 10.2.3-h13, 10.2.2-h5, 10.2.1-h2, and 10.2.0-h3.
  • PAN-OS 11.0: 11.0.4-h1, 11.0.4-h2, 11.0.3-h10, 11.0.2-h4, 11.0.1-h4, and 11.0.0-h3.
  • PAN-OS 11.1: 11.1.2-h3, 11.1.1-h1, and 11.1.0-h3.
  1. If an upgrade cannot be completed immediately, apply the confirmed mitigation. Customers with a Threat Prevention subscription can use Threat IDs 95187, 95189, and 95191, available with Applications and Threats content version 8836-8695 and later, and must apply vulnerability protection to the GlobalProtect interface. This is a mitigation, not a replacement for upgrading.

  2. Do not rely on disabling device telemetry. Palo Alto Networks states that telemetry does not need to be enabled for a firewall to be exposed, so disabling telemetry is no longer an effective mitigation.

  3. Preserve evidence if exploitation or compromise is suspected. Do not wipe or rebuild the appliance before collecting logs, a Tech Support File, and forensic evidence. Contact Palo Alto Networks Support or TAC for investigation guidance and to assess whether an enhanced factory reset is needed. Fixes and mitigations do not automatically remediate an existing compromise.

  4. Extend the investigation into the internal network. Review lateral movement, consider changing passwords and secrets stored on the firewall, and assess systems that may have been accessed from the GlobalProtect device.

Detection

Checks should cover both exposure and evidence that a device was targeted or compromised:

  • Inventory every firewall running PAN-OS with a GlobalProtect gateway or portal, then compare its release with the affected and fixed branches in Affected Summary.
  • On a GlobalProtect firewall, review mp-log/gpsvc.log* using the check published by Palo Alto Networks:

grep pattern "failed to unmarshal session(.\+\.\/" mp-log gpsvc.log*

If the value between session( and ) does not resemble a GUID and instead contains a filesystem path or shell commands, treat it as suspicious and investigate it with other evidence.

  • Collect and preserve the Tech Support File, relevant logs, and forensic evidence before wiping, rebuilding, or resetting the device. The TSF can help identify traces of attempted exploitation or compromise.
  • Review traffic originating from the firewall, especially direct-to-IP HTTP requests used to download files with wget, unexpected SMB or RDP connections to multiple internal systems, and transfers of browser data or ntds.dit over SMB. These patterns were observed during investigated compromises and are not proof that every device showing them was exploited.
  • Additional monitoring for abnormal network activity is a precaution. The absence of a listed log entry or indicator must not be treated as proof that the device is safe.
Sources (14)
palo_alto (CNA)
Learn more

Run an in-depth assessment with complete web risk management

CyStack VulnScan continuously discovers assets, validates vulnerabilities, and helps security teams prioritize remediation across the organization.

Explore CyStack VulnScan
CyStack VulnScan dashboard