Sploitus

CVE-2024-3400

44 known exploits for CVE-2024-3400

A command injection as a result of arbitrary file creation vulnerability in the GlobalProtect feature of Palo Alto Networks PAN-OS software for specific PAN-OS versions and distinct feature configurations may enable an unauthenticated attacker to execute arbitrary code with root privileges on the firewall. Cloud NGFW, Panorama appliances, and Prisma Access are not impacted by this vulnerability.

Affected products
Pan-Os
Paloaltonetworks Pan-os
= 10.2.0, 10.2.1, 10.2.2, 10.2.3, 10.2.4, 10.2.5, 10.2.6, 10.2.7, 10.2.8, 10.2.9, 11.0.0, 11.0.1, 11.0.2, 11.0.3, 11.0.4, 11.1.0, 11.1.1, 11.1.2
Fix
Available
CVSS 3.1
10.0 CRITICAL
EPSS
100.0% (100th percentile)
Weakness
CWE-77, CWE-20
NVD status
Analyzed
Published
2024-04-12
Attack patterns
CAPEC-248
Entry point
SESSID (cookie) path
Path
global-protect/portal/fonts/glyphicons-abcdefgh-regular.woff2

Fix

We strongly advise customers to immediately upgrade to a fixed version of PAN-OS to protect their devices even when workarounds and mitigations have been applied. This issue is fixed in PAN-OS 10.2.9-h1, PAN-OS 11.0.4-h1, PAN-OS 11.1.2-h3, and in all later PAN-OS versions. Customers who upgrade to these versions will be fully protected.

Workaround

Recommended Mitigation: Customers with a Threat Prevention subscription can block attacks for this vulnerability using Threat IDs 95187, 95189, and 95191 (available in Applications and Threats content version 8836-8695 and later). Please monitor this advisory and new Threat Prevention content updates for additional Threat Prevention IDs around CVE-2024-3400. To apply the Threat IDs, customers must ensure that vulnerability protection has been applied to their GlobalProtect interface to prevent exploitation of this issue on their device. Please see https://live.paloaltonetworks.com/t5/globalprotect-articles/applying-vulnerability-protection-to-globalprotect-interfaces/ta-p/340184 for more information.

CVE-2024-3400 at NVD
Authoritative description, scoring and affected products

44 known exploits for CVE-2024-3400

Proof-of-concept code and exploit modules indexed by Sploitus

Exploit for Command Injection in Paloaltonetworks Pan-Os
2026-07-24 razureinkGITHUB
Exploit for Improper Input Validation in Paloaltonetworks Pan-Os
2026-05-30 Nikki-the-ParcelGITHUB
Exploit for Improper Input Validation in Paloaltonetworks Pan-Os
2026-05-30 Nikki-the-ParcelGITHUB
CTT-enhanced-Dirty-Frag-exploit
2026-05-08 SimoesCTTGITHUB
Exploit for Command Injection in Paloaltonetworks Pan-Os
2026-04-20 wa6n3rGITHUB
Exploit for Command Injection in Paloaltonetworks Pan-Os
2026-04-06 SimoesCTTGITHUB
Exploit for Command Injection in Paloaltonetworks Pan-Os
2026-03-30 xiexie-qiuligaoGITHUB
Exploit for Improper Input Validation in Paloaltonetworks Pan-Os
2025-06-08 CyberBibsGITHUB
Exploit for Improper Input Validation in Paloaltonetworks Pan-Os
2025-01-10 XiaomingXGITHUB
Exploit for Improper Input Validation in Paloaltonetworks Pan-Os
2024-05-12 andrelia-hacksGITHUB
Exploit for Improper Input Validation in Paloaltonetworks Pan-Os
2024-04-27 marconeslerGITHUB
Exploit for Improper Input Validation in Paloaltonetworks Pan-Os
2024-04-25 0xr2rGITHUB
Exploit for Improper Input Validation in Paloaltonetworks Pan-Os
2024-04-24 zam89GITHUB
Palo Alto PAN-OS Command Execution / Arbitrary File Creation
2024-04-23 Kr0ffPACKETSTORMPython
Palo Alto Networks PAN-OS Unauthenticated Remote Code Execution
2024-04-23 sfewer-r7, remmons-r7, metasploit.comPACKETSTORMRuby
Palo Alto Networks PAN-OS Unauthenticated Remote Code Execution Exploit
2024-04-23 metasploitZDTRuby
Exploit for Improper Input Validation in Paloaltonetworks Pan-Os
2024-04-21 Kr0ffGITHUB
Palo Alto PAN-OS < v11.1.2-h3 - Command Injection and Arbitrary File Creation Exploit
2024-04-21 Kr0ffZDTPython
Palo Alto PAN-OS < v11.1.2-h3 - Command Injection and Arbitrary File Creation
2024-04-21 Kr0ffEXPLOITDBPython
Palo Alto Networks PAN-OS Unauthenticated Remote Code Execution
2024-04-19 remmons-r7, sfewer-r7METASPLOITRuby
Exploit for Improper Input Validation in Paloaltonetworks Pan-Os
2024-04-19 pwnj0hnGITHUB
Exploit for Improper Input Validation in Paloaltonetworks Pan-Os
2024-04-18 swaybsGITHUB
Exploit for Improper Input Validation in Paloaltonetworks Pan-Os
2024-04-18 codeblueprintGITHUB
Exploit for Improper Input Validation in Paloaltonetworks Pan-Os
2024-04-18 schooldropout1337GITHUB
Exploit for Improper Input Validation in Paloaltonetworks Pan-Os
2024-04-17 retkoussaGITHUB
Exploit for Improper Input Validation in Paloaltonetworks Pan-Os
2024-04-17 ak1t4GITHUB
Exploit for Improper Input Validation in Paloaltonetworks Pan-Os
2024-04-17 ZephrFishGITHUB
Palo Alto OS Command Injection
2024-04-17 h4x0r-dz, github.comPACKETSTORM
Palo Alto OS Command Injection Vulnerability
2024-04-17 h4x0r-dzZDT
Exploit for Improper Input Validation in Paloaltonetworks Pan-Os
2024-04-16 ihebskiGITHUB
Exploit for Improper Input Validation in Paloaltonetworks Pan-Os
2024-04-16 ChocapikkGITHUB
Exploit for Improper Input Validation in Paloaltonetworks Pan-Os
2024-04-16 CONDITIONBLACKGITHUB
Exploit for Improper Input Validation in Paloaltonetworks Pan-Os
2024-04-16 W01fh4ckerGITHUB
Exploit for Improper Input Validation in Paloaltonetworks Pan-Os
2024-04-16 W01fh4ckerGITHUB
Exploit for Improper Input Validation in Paloaltonetworks Pan-Os
2024-04-16 W01fh4ckerGITHUB
Exploit for Improper Input Validation in Paloaltonetworks Pan-Os
2024-04-16 LoanVitorGITHUB
Exploit for Improper Input Validation in Paloaltonetworks Pan-Os
2024-04-16 AdaniKamalGITHUB
Exploit for Improper Input Validation in Paloaltonetworks Pan-Os
2024-04-15 MurrayR0123GITHUB
Exploit for Improper Input Validation in Paloaltonetworks Pan-Os
2024-04-15 MurrayR0123GITHUB
Exploit for Improper Input Validation in Paloaltonetworks Pan-Os
2024-04-14 momika233GITHUB
Exploit for Improper Input Validation in Paloaltonetworks Pan-Os
2024-04-13 0x0d3adGITHUB
Exploit for Improper Input Validation in Paloaltonetworks Pan-Os
2024-04-13 CerTusHackGITHUB
Exploit for Improper Input Validation in Paloaltonetworks Pan-Os
2024-04-13 Yuvvi01GITHUB
CVE-2024-3400
2024-04-12 palo_altoUNKNOWN