CVE-2024-3400 PAN-OS: Arbitrary File Creation Leads to OS Command Injection Vulnerability in GlobalProtect
🔗 CVE IDs covered (1)
📋 Description
A command injection as a result of arbitrary file creation vulnerability in the GlobalProtect feature of Palo Alto Networks PAN-OS software for specific PAN-OS versions and distinct feature configurations may enable an unauthenticated attacker to execute arbitrary code with root privileges on the firewall. Cloud NGFW, Panorama appliances, and Prisma Access are not impacted by this vulnerability. Customers should continue to monitor this security advisory for the latest updates and product guidance.
🎯 Affected products3
- PAN-OS
- Cloud NGFW
- Prisma Access
✅ Remediation
We strongly advise customers to immediately upgrade to a fixed version of PAN-OS to protect their devices even when workarounds and mitigations have been applied. This issue is fixed in PAN-OS 10.2.9-h1, PAN-OS 11.0.4-h1, PAN-OS 11.1.2-h3, and in all later PAN-OS versions. These fixes and those listed below completely prevent the initial remote command execution, stopping subsequent post-exploitation or persistence. In addition, to provide the most seamless upgrade path for customers, additional hotfixes have been made available as a courtesy for other commonly deployed maintenance releases. PAN-OS 10.2: - 10.2.9-h1 (Released 4/14/24) - 10.2.8-h3 (Released 4/15/24) - 10.2.7-h8 (Released 4/15/24) - 10.2.6-h3 (Released 4/16/24) - 10.2.5-h6 (Released 4/16/24) - 10.2.4-h16 (Released 4/18/24) - 10.2.3-h13 (Released 4/18/24) - 10.2.2-h5 (Released 4/18/24) - 10.2.1-h2 (Released 4/18/24) - 10.2.0-h3 (Released 4/18/24) PAN-OS 11.0: - 11.0.4-h1 (Released 4/14/24) - 11.0.4-h2 (Released 4/17/24) - 11.0.3-h10 (Released 4/16/24) - 11.0.2-h4 (Released 4/16/24) - 11.0.1-h4 (Released 4/18/24) - 11.0.0-h3 (Released 4/18/24) PAN-OS 11.1: - 11.1.2-h3 (Released 4/14/24) - 11.1.1-h1 (Released 4/16/24) - 11.1.0-h3 (Released 4/16/24) Note: Due to naming convention limitations, “-h” hotfix versions on Azure marketplace are instead named via addition of an extra “0”. Ex: 11.1.2-h3 is published on Azure as 11.1.203. If any exploitation was observed on a device, please take the remediation steps suggested here: https://knowledgebase.paloaltonetworks.com/KCSArticleDetail?id=kA14u000000CrO6CAK An enhanced factory reset (EFR) procedure that does not rely on the integrity of a potentially compromised device can be scheduled by opening a case through Customer Support (TAC). This is recommended for: 1. Customers who have not applied the PAN-OS fixes or Threat Prevention signatures with vulnerability protection applied to the GlobalProtect interface (regardless of level of compromise) on or before April 25, 2024; or 2. Customers who are concerned about a persistent risk. Workarounds and mitigations: Recommended Mitigation: Customers with a Threat Prevention subscription can block attacks for this vulnerability using Threat IDs 95187, 95189, and 95191 (available in Applications and Threats content version 8836-8695 and later). Please monitor this advisory and new Threat Prevention content updates for additional Threat Prevention IDs around CVE-2024-3400. To apply the Threat IDs, customers must ensure that vulnerability protection has been applied to their GlobalProtect interface to prevent exploitation of this issue on their device. Please see https://live.paloaltonetworks.com/t5/globalprotect-articles/applying-vulnerability-protection-to-globalprotect-interfaces/ta-p/340184 for more information. In earlier versions of this advisory, disabling device telemetry was listed as a secondary mitigation action. Disabling device telemetry is no longer an effective mitigation. Device telemetry does not need to be enabled for PAN-OS firewalls to be exposed to attacks related to this vulnerability.