Skip to main content

A critical vulnerability in Palo Alto Networks PAN-OS CVE-2024-3400


Stabz
Forum|alt.badge.img+8
  • On the path to Greatness
  • 354 comments

Hey folks,
 

A critical vulnerability (CVSS: 10) referenced as CVE-2024-3400, impacting a feature in Palo Alto Networks PAN-OS, allows an unauthenticated user to execute code with administrator privileges on the firewall. Please be aware that this vulnerability is actively being exploited.

Affected system:

  • PAN-OS 11.1.x versions antérieures à 11.1.2-h3
  • PAN-OS 11.0.x versions antérieures à 11.0.4-h1
  • PAN-OS 10.2.x antérieures à 10.2.9-h1

Remediation:
Apply security patches, available for certain versions since April 14, 2024.
If the patch is not yet available for the installed version, the workaround is to disable telemetry on the firewall, or enable threat protection with ID 95187 in the "Threat Prevention" function.

More infos:

https://security.paloaltonetworks.com/CVE-2024-3400

1 comment

Chris.Childerhose
Forum|alt.badge.img+21
  • Veeam Legend, Veeam Vanguard
  • 8492 comments
  • April 23, 2024

Interesting a vendor that you don't hear much about but nice to see they have patched the issue.  Always liked learning about Palo Alto networking firewalls.


Comment