CVE-2024-3400: Critical Vulnerability in GlobalProtect Feature of PAN-OS being Actively Exploited
ID: 492578ea-0e40-56f4-9ddf-e01ef29d3990
STIX ID: report--492578ea-0e40-56f4-9ddf-e01ef29d3990
Feed Name: Arctic Wolf
On April 12, 2024 Palo Alto Networks disclosed an actively exploited PAN-OS zero-day (CVE-2024-3400, CVSS 10.0) in the GlobalProtect feature that permits unauthenticated remote code execution as root on affected PAN-OS 10.2, 11.0, and 11.1 devices; Volexity attributed exploitation to threat actor UTA0218 which deployed a Python backdoor called UPSTYLE and performed lateral movement and credential/file theft. Palo Alto Networks is developing hotfixes expected by April 14, 2024 and recommends enabling vulnerability protection (Threat ID 95187), verifying GlobalProtect interface protections, or temporarily disabling device telemetry as workarounds until patches are applied.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
