CVE-2024-3400: Critical Vulnerability in GlobalProtect Feature of PAN-OS being Actively Exploited
ID: c2956f9c-9a10-597e-b530-c48d5e103f77
STIX ID: report--c2956f9c-9a10-597e-b530-c48d5e103f77
Feed Name: Arctic Wolf
On 12 April 2024 Palo Alto Networks disclosed CVE-2024-3400, a critical (CVSS 10.0) GlobalProtect PAN-OS vulnerability affecting versions 10.2, 11.0 and 11.1 that allows unauthenticated remote code execution as root; Volexity reported active exploitation by threat actor UTA0218 that deployed a UPSTYLE Python backdoor, conducted lateral movement, and exfiltrated credentials and files, while Palo Alto prepared hotfixes and recommended interim mitigations (Threat ID 95187 and disabling device telemetry).
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
