Zero-Day Alert: Critical Palo Alto Networks PAN-OS Flaw Under Active Attack
ID: 165b8851-3825-5205-acb8-ee5882c40a4c
STIX ID: report--165b8851-3825-5205-acb8-ee5882c40a4c
Feed Name: The Hacker News
Threat Score
Palo Alto Networks warns of CVE-2024-3400, a critical (CVSS 10.0) command-injection zero-day in PAN-OS GlobalProtect gateways that can allow unauthenticated remote root code execution; it is being actively exploited in the wild. The issue affects PAN-OS versions <11.1.2-h3, <11.0.4-h1, and <10.2.9-h1 when both GlobalProtect gateway and device telemetry features are enabled, with mitigations (Threat ID 95187) recommended and vendor fixes expected on April 14, 2024.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
