📣 Send us your press release
Site updates every 15 minutes
Technology

Palo Alto PAN-OS System Contains Critical Command Injection Vulnerability

Picus Security has analyzed the critical CVE-2024-3400 vulnerability in Palo Alto's PAN-OS, allowing remote attackers to execute commands with root privileges on firewall devices.

1 October 2026

Cybersecurity firm Picus Security has analyzed the critical CVE-2024-3400 vulnerability affecting Palo Alto Networks' PAN-OS operating system. Disclosed in April 2024, the vulnerability carries a CVSS score of 10.0, classifying it as critical. It enables remote attackers to execute commands with root privileges on network devices.

The vulnerability impacts PAN-OS versions utilized in Palo Alto's firewall appliances. Threat actors can exploit CVE-2024-3400 for initial access, persistence, data exfiltration, or lateral movement within compromised networks. Picus Security urges organizations to patch their vulnerable PAN-OS software without delay.

The analysis reveals the vulnerability resides in the GlobalProtect feature's telemetry functionality. Attackers can send crafted HTTP POST requests containing commands via the SESSID cookie. These commands are executed at the root level, a fact confirmed in real-world attacks by threat actor UTA0218, according to research by Volexity.

Picus Security highlights that exploitation can lead to the deployment of a Python-based backdoor named UPSTYLE, used to establish persistent access. The company provides tools and simulations to help organizations test and improve their defenses against such threats.

Original source: picussecurity.com