Exploitation of vulnerability affecting Palo Alto GlobalProtect Gateway
The NCSC is encouraging organisations to take immediate action to mitigate a vulnerability affecting Palo Alto GlobalProtect Gateway and to follow the latest vendor advice.
Updated: 22 April 2024
What has happened?
Palo Alto has published a security advisory detailing a vulnerability affecting the GlobalProtect feature of Palo Alto Networks PAN-OS software (CVE-2024-3400).
CVE-2024-3400 is a command injection vulnerability in the GlobalProtect feature of Palo Alto Networks PAN-OS software for specific PAN-OS versions. Distinct feature configurations may enable an unauthenticated attacker to execute arbitrary code with root privileges on the firewall.
The NCSC will continue to monitor for any impact of this vulnerability on UK organisations.
Who is affected?
This vulnerability only affects PAN-OS 10.2, PAN-OS 11.0, and PAN-OS 11.1 firewalls configured with GlobalProtect gateway or GlobalProtect portal, or both.
Exploitation
Palo Alto Networks is aware of increasing exploitation of this vulnerability. Proof of concepts for this vulnerability have been publicly disclosed by third parties.
The NCSC recommends following vendor best practice advice to mitigate vulnerabilities. In this case, if you use PAN-OS GlobalProtect gateway and/or portal, you should take these priority actions:
Monitor the vendor advisory and install the security update once it is available for your version (and remove any temporary mitigation).
If your organisation is in the UK, you can sign up to the free NCSC Early Warning service to receive notifications of potential cyber attacks on your network.
The NCSC Vulnerability Disclosure Toolkit helps organisations of all sizes with the essential components of implementing a vulnerability disclosure process