Critical zero-day vulnerability CVE-2024-3400 in Palo Alto firewalls exploited on 6,634 devices, allowing root access
Apr 12, 2024In April 2024, a command injection vulnerability CVE-2024-3400 with CVSS score of 10 allowed unauthenticated attackers to execute arbitrary code with root privileges on Palo Alto Networks firewalls. The vulnerability impacted the GlobalProtect gateway/portal VPN feature on PAN-OS devices. Shadowserver Foundation scanning found 6,634 devices vulnerable and likely exploited. Additional November 2024 vulnerabilities led to about 2,000 firewalls breached worldwide.