Skip to main content

Palo Alto Networks patches zero-day CVE-2024-3400 in PAN-OS

Palo Alto Networks detailed the exploitation of CVE-2024-3400 in specific PAN-OS configurations with GlobalProtect.

CybersecuritySeintec Team2-3 min read
Palo Alto Networks patches zero-day CVE-2024-3400 in PAN-OS

News summary

Palo Alto Networks detailed the exploitation of CVE-2024-3400 in specific PAN-OS configurations with GlobalProtect. The company observed real-world attacks and released mitigations and hotfixes to block remote command execution.

Security devices are also software and require continuous management. Firmware, configurations, Internet exposure, and administration alerts must be reviewed periodically.

Source: Palo Alto Networks — 19 April 2024

What happened

Palo Alto Networks confirmed in April 2024 the active exploitation of CVE-2024-3400, a critical vulnerability in certain PAN-OS configurations with GlobalProtect that allowed unauthenticated remote command execution.

The company detected real-world attacks before releasing the definitive fix and provided hotfixes and temporary mitigations for affected devices while the patching process was completed.

What it means for a mid-sized business

A firewall or VPN is also software, with its own vulnerabilities and update cycles. If that device sits on the perimeter and provides remote access, a critical flaw in it can compromise the entire internal network without anything else needing to be breached.

Many businesses manage their security appliances as fixed elements requiring no maintenance, when in reality they need the same patching discipline as any server or application.

What to review

When a critical vulnerability affects a perimeter device, it's worth checking:

  • What firmware or operating system version each firewall or VPN runs and whether it still has vendor support.
  • Whether the management console of those devices is unnecessarily exposed directly to the internet.
  • How the organisation receives and acts on the vendor's security advisories.
  • How long typically passes between a critical patch being published and actually being applied.

Frequently Asked Questions

What did this vulnerability allow?
It allowed an attacker to execute commands remotely without authentication on specific PAN-OS configurations with GlobalProtect.
Did it only affect large organisations?
No. It affected any organisation running the vulnerable configurations, regardless of size.
How does a business protect itself against this kind of flaw?
By keeping firmware up to date, limiting exposure of the admin panel to the internet and applying critical patches as soon as they are released.

This type of news demonstrates that cybersecurity, cloud, and business continuity must be planned jointly. Seintec can help you achieve this in your organisation; please contact us.

Contact Seintec

Related service

Cybersecurity

We shield your business so it never stops.

Next step

Would you like to implement these improvements in your company?

Speak with a Seintec expert and we will review how this applies to your infrastructure together.