CVE-2024-3400: Palo Alto Networks PAN-OS Command Injection Vulnerability

Critical severity, CVSS 10.0. Actively exploited: in CISA KEV since 2024-04-12. EPSS: 100% chance of exploitation in the next 30 days.

A command injection as a result of arbitrary file creation vulnerability in the GlobalProtect feature of Palo Alto Networks PAN-OS software for specific PAN-OS versions and distinct feature configurations may enable an unauthenticated attacker to execute arbitrary code with root privileges on the firewall. Cloud NGFW, Panorama appliances, and Prisma Access are not impacted by this vulnerability.

Affected products

  • Palo Alto Networks PAN-OS: version 10.2.0 only; version 10.2.1 only; version 10.2.2 only; version 10.2.3 only; version 10.2.4 only; version 10.2.5 only; …

Published 2024-04-12. Last modified 2026-06-17.