← volver
CVE-2024-3400

PAN-OS: Arbitrary File Creation Leads to OS Command Injection Vulnerability in GlobalProtect

CVSS 10 CRITICALEPSS 100.0%● KEVCWE-20CWE-77
En resumen

Una falla en la función GlobalProtect de Palo Alto Networks permite que atacantes sin autenticación creen archivos en el firewall e inyecten comandos para tomar control total del dispositivo con acceso de administrador.

Detalle técnico

Un atacante remoto no autenticado puede explotar validación inadecuada de entrada (CWE-20) e inyección de comando (CWE-77) en GlobalProtect para crear archivos arbitrarios en el firewall, resultando en ejecución de comandos del SO con privilegios root. La explotación requiere versiones específicas de PAN-OS y configuraciones particulares; Cloud NGFW, Panorama y Prisma Access no se ven afectados.

Resumen generado y traducido por IA a partir de la descripción oficial.
A command injection as a result of arbitrary file creation vulnerability in the GlobalProtect feature of Palo Alto Networks PAN-OS software for specific PAN-OS versions and distinct feature configurations may enable an unauthenticated attacker to execute arbitrary code with root privileges on the firewall. Cloud NGFW, Panorama appliances, and Prisma Access are not impacted by this vulnerability.
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H
PoCs públicas encontradas43
githubgithub.com/h4x0r-dz/CVE-2024-3400161githubgithub.com/W01fh4cker/CVE-2024-3400-RCE-Scan90githubgithub.com/0x0d3ad/CVE-2024-340070githubgithub.com/ihebski/CVE-2024-340033githubgithub.com/Chocapikk/CVE-2024-340015githubgithub.com/momika233/CVE-2024-340013githubgithub.com/Yuvvi01/CVE-2024-340011githubgithub.com/ak1t4/CVE-2024-34009githubgithub.com/AdaniKamal/CVE-2024-34007githubgithub.com/schooldropout1337/CVE-2024-34006githubgithub.com/0xr2r/CVE-2024-3400-Palo-Alto-OS-Command-Injection6githubgithub.com/zam89/CVE-2024-3400-pot6githubgithub.com/retkoussa/CVE-2024-34005githubgithub.com/HackingLZ/panrapidcheck2githubgithub.com/CerTusHack/CVE-2024-3400-PoC2githubgithub.com/ZephrFish/CVE-2024-3400-Canary2githubgithub.com/swaybs/CVE-2024-34002githubgithub.com/marconesler/CVE-2024-34002githubgithub.com/CONDITIONBLACK/CVE-2024-3400-POC1githubgithub.com/Zedocun/PAN-OS-CVE-2024-3400-Command-Injection-Investigation1githubgithub.com/wa6n3r/CVE-2024-34001githubgithub.com/hashdr1ft/SOC274-Palo-Alto-Networks-PAN-OS-Command-Injection-Vulnerability-Exploitation-CVE-2024-34001githubgithub.com/sxyrxyy/CVE-2024-3400-Check0githubgithub.com/Ravaan21/CVE-2024-34000githubgithub.com/tfrederick74656/cve-2024-3400-poc0githubgithub.com/pwnj0hn/CVE-2024-34000githubgithub.com/MurrayR0123/CVE-2024-3400-Compromise-Checker0githubgithub.com/Kr0ff/cve-2024-34000githubgithub.com/MrR0b0t19/CVE-2024-34000githubgithub.com/terminalJunki3/CVE-2024-3400-Checker0githubgithub.com/LoanVitor/CVE-2024-3400-0githubgithub.com/andrelia-hacks/CVE-2024-34000githubgithub.com/ivan-n0v/cve-2024-34000githubgithub.com/workshop748/CVE-2024-34000githubgithub.com/CyprianAtsyor/letsdefend-cve2024-3400-case-study0githubgithub.com/CyberBibs/SOC274---Palo-Alto-Networks-PAN-OS-Command-Injection-Vulnerability-Exploitation-CVE-2024-3400-0githubgithub.com/Yafiah-Darwesh/cs50-cyber-paloalto-oauth0githubgithub.com/index2014/CVE-2024-3400-Checker0githubgithub.com/FoxyProxys/CVE-2024-34000githubgithub.com/hahasagined/CVE-2024-34000githubgithub.com/codeblueprint/CVE-2024-34000githubgithub.com/P4rC3L/Global-Protect_VPN_Vuln0exploitdbwww.exploit-db.com/exploits/51996no verificado
⚠ Recursos públicos, para evaluar la exposición de sistemas que controlas o estás autorizado a probar. Prueba solo con autorización.

¿Quieres saber si tu infraestructura está expuesta a esto?

Hablar con TrueHacking →