VulnCity

Palo Alto PAN-OS Command Injection — Zero-Day فعال

  • شناسه CVE: CVE-2024-3400
  • شدت: بحرانی
  • امتیاز CVSS: 10
  • فروشنده/سازنده: Palo Alto Networks
Command InjectionPAN-OSZero-DayAPTFirewallCritical
CVE-2024-3400 is a maximum severity (CVSS 10.0) OS command injection zero-day in Palo Alto Networks PAN-OS GlobalProtect Gateway, actively exploited by nation-state threat actors before patch availability.

## Vulnerability Overview
A command injection vulnerability in the GlobalProtect feature of PAN-OS allows an unauthenticated attacker to execute arbitrary OS commands with root privileges. The vulnerability is triggered via a crafted SESSID cookie value in HTTP requests to the GlobalProtect portal/gateway.

## Technical Details
- **Type:** OS Command Injection (CWE-77)
- **Vulnerable Component:** GlobalProtect Gateway / Portal (HTTPS)
- **Root Cause:** Two separate bugs chained together:
1. An arbitrary file creation bug allows writing a file with attacker-controlled name/content.
2. A command injection in the telemetry processing pipeline executes the attacker-controlled filename as a shell command.
- **Trigger:** Crafted SESSID cookie containing shell metacharacters and a path traversal sequence.
- **Privileges:** Root — PAN-OS GlobalProtect runs as root.

## Exploitation in the Wild (Operation MidnightEclipse)
- Exploited as a zero-day by UTA0218 (suspected nation-state actor) since March 26, 2024.
- Attackers deployed a Python-based backdoor named UPSTYLE.
- Used for espionage, credential theft, and lateral movement into internal networks.
- CISA added to KEV catalog on day of disclosure.

## Affected Versions
- PAN-OS 10.2.x (< 10.2.9-h1)
- PAN-OS 11.0.x (< 11.0.4-h1)
- PAN-OS 11.1.x (< 11.1.2-h3)
- **Requires:** GlobalProtect gateway or portal enabled

نرم‌افزارهای تحت تأثیر

  • PAN-OS 10.2.x
  • PAN-OS 11.0.x
  • PAN-OS 11.1.x