CVE-2024-3400: Follow Up: Patches Released for Actively Exploited Critical Vulnerability in GlobalProtect Feature of PAN-OS
ID: 5cb207b9-5f2b-531b-a8d7-0e910ebf87fe
STIX ID: report--5cb207b9-5f2b-531b-a8d7-0e910ebf87fe
Feed Name: Arctic Wolf
On 14 April 2024 Palo Alto Networks released hotfixes for CVE-2024-3400, a CVSS 10 vulnerability in the GlobalProtect feature that allows unauthenticated remote code execution as root; Volexity reported active exploitation by threat actor UTA0218 implanting a custom Python backdoor to download additional tools and exfiltrate credentials and files. Arctic Wolf strongly recommends upgrading affected PAN-OS versions to the listed fixed releases and provides mitigations (Threat ID 95187, vulnerability protection on GlobalProtect interfaces, or temporarily disabling device telemetry) until devices are patched.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
