CVE-2024-3400
CRITICAL
Actively Exploited
paloaltonetworks
NVDCISA KEV
CVSS Score
10
Severity
CRITICAL
Published
Apr 12, 2024
Vendor
paloaltonetworks
This vulnerability is in the CISA Known Exploited Vulnerabilities Catalog. Active exploitation has been observed. Immediate patching is recommended.
Description
A command injection as a result of arbitrary file creation vulnerability in the GlobalProtect feature of Palo Alto Networks PAN-OS software for specific PAN-OS versions and distinct feature configurations may enable an unauthenticated attacker to execute arbitrary code with root privileges on the firewall.