Skip to content

PAN-OS GlobalProtect (CVE-2024-3400)

CVE-2024-3400CWE-77OWASP A03:2021CVSS 10.0Updated October 1, 20262 min read

CVE-2024-3400 is a command injection in the GlobalProtect feature of PAN-OS, reachable through a GlobalProtect gateway or portal. An unauthenticated attacker could run commands as root on the firewall that was supposed to protect the network. It scores 10.0. The flaw was already being exploited in targeted attacks more than two weeks before the advisory.

Affected
PAN-OS 10.2, 11.0 and 11.1 with a GlobalProtect gateway or GlobalProtect portal (or both) configured; device telemetry does not need to be enabled
Patched in
PAN-OS 10.2.9-h1, 11.0.4-h1, 11.1.2-h3 and all later versions
Actively exploited
yes

In April 2024 it emerged that attackers had been getting into Palo Alto Networks firewalls since late March. They used a flaw in exactly the component organisations rely on to let staff log in safely from outside.

What is CVE-2024-3400

GlobalProtect used the value of a session cookie to build a file path without validating it. With a crafted cookie, an unauthenticated attacker could create an empty file anywhere on the file system, with a name of their choosing. That alone executes nothing. The command injection came from a separate process on the appliance that later passed such file names to a shell: a name containing shell commands was executed, and as root, because that is how the process runs. Palo Alto therefore describes the flaw as command injection resulting from arbitrary file creation.

This is remote code execution in its purest form: no account, no interaction, complete control.

What the attackers did

Volexity discovered the attacks on 10 April 2024 at one of its customers and tracks the actor behind them as UTA0218. Palo Alto’s own threat intelligence team, Unit 42, calls the campaign Operation MidnightEclipse. Volexity’s earliest evidence dates from 26 March, when the attacker appeared to be testing the exploit. The attackers installed a backdoor that read commands out of the web server’s error log and returned the output in a CSS file that passed as a legitimate part of the appliance. That gave them a control channel barely visible in ordinary logging.

Then came the usual sequence: read the configuration, harvest credentials, and step from the firewall into the internal network. Volexity considers it highly likely that UTA0218 is state-backed. In August 2025 CISA and partner agencies also listed CVE-2024-3400 among the vulnerabilities exploited by Chinese state-sponsored actors.

Why the edge is increasingly the target

VPN concentrators, firewalls and gateways share three properties attackers like. They are always internet-facing, they hold broad rights inside the network, and they often run no detection software because they are closed appliances. A breach there is far harder to see than a breach on a workstation.

What to do now

  • PAN-OS 11.0 reached end-of-life in November 2024. Standard support for 10.2 ended in August 2025, leaving only extended support until March 2027. Run a release line that still has standard support, at the time of writing 11.1 or later, on its latest maintenance release. The 2024 hotfixes are a minimum, not a target.
  • Never expose management interfaces of network equipment directly to the internet. See also security misconfiguration.
  • Include edge appliances in your log collection. If nothing is shipped off the device, you learn about a breach when somebody else notices it.
  • With a critical flaw in edge equipment, assume exploitation has already happened and go looking for it, rather than only patching.

Sources

Frequently asked questions

Why is a flaw in a firewall especially serious?

A firewall is internet-facing by definition and sees all the traffic behind it. Getting root on one puts you not at the edge of the network but in its control room.

Was everyone running PAN-OS affected?

No. Only PAN-OS 10.2, 11.0 and 11.1 firewalls with a GlobalProtect gateway or portal configured. Palo Alto's first advisory also required device telemetry, but the current advisory states that telemetry does not need to be enabled. That still covered precisely the organisations using the appliance for remote access.

Was patching enough?

Only if nobody had got in yet. Palo Alto advised checking for signs of compromise after patching, because an attacker who arrived earlier may have left their own access behind.

Related articles

Press / to search · Esc