Palo Alto Networks PAN-OS firewalls have faced a new wave of exploitation attempts following the disclosure of CVE-2024-3400 on April 12.Unit 42, Palo Alto Networks’ threat intelligence team, updated its threat brief Friday to include information on the current scope of attacks targeting the critical command injection vulnerability.The vulnerability, which lies in the PAN-OS GlobalProtect feature and has a maximum CVSS score of 10, originally came under attack as a zero-day by a suspected state-sponsored actor known as UTA0218, Volexity discovered. Unit 42 now says it is aware of “an increasing number of attacks” following the publication of proof-of-concept exploits for CVE-2024-3400 last week. Additionally, attacks seemingly unrelated to the original UTA0218 campaign have been detected. Meanwhile, approximately 6,200 GlobalProtect instances remained vulnerable to CVE-2024-3400 as of April 21, according to data from security organization Shadowserver. These instances were confirmed by Shadowserver to be vulnerable based on the “existence of files left behind by exploits.”The PAN-OS GlobalProtect vulnerability was fixed with the releases of PAN-OS 10.2.9-h1, PAN-OS 11.0.4-h1 and PAN-OS 11.1.2-h3 on April 14. Additional hotfixes for commonly used maintenance releases were also rolled out between April 15 and April 18.Palo Alto Networks said in a blog post Friday that Threat Prevention customers can use Threat IDs 95187, 95189 and 95191 to block attacks targeting the vulnerability with “100% accuracy,” and that 90% of susceptible PAN-OS devices are now protected.The company previously said disabling telemetry was a mitigation for the vulnerability, but says this no longer guarantees protection due to the discovery of potential exploits that do not require telemetry to be enabled for a successful attack.
Network Security, Patch/Configuration Management, Endpoint/Device Security
6.2K Palo Alto firewalls still at risk as exploits increase

(Credit: piter2121 – stock.adobe.com)
An In-Depth Guide to Network Security
Get essential knowledge and practical strategies to fortify your network security.
Related Events
Get daily email updates
SC Media's daily must-read of the most current and pressing daily news
You can skip this ad in 5 seconds