Answer in brief
CVE-2024-3400 records a High severity vulnerability in PAN-OS: Arbitrary File Creation Leads to OS Command Injection Vulnerability in GlobalProtect. The current sources mark it as known exploited. The current feed maps paloaltonetworks/pan-os (generic), paloaltonetworks/pan-os (generic), paloaltonetworks/pan-os (generic), Palo Alto Networks/PAN-OS (generic). Check affected ranges and fixed versions before updating.
Analysis pending evidence review
HOL Guard separates source facts from reviewed analysis. See the methodology.
Answer in brief
CVE-2024-3400 records a High severity vulnerability in PAN-OS: Arbitrary File Creation Leads to OS Command Injection Vulnerability in GlobalProtect. The current sources mark it as known exploited. The current feed maps paloaltonetworks/pan-os (generic), paloaltonetworks/pan-os (generic), paloaltonetworks/pan-os (generic), Palo Alto Networks/PAN-OS (generic). Check affected ranges and fixed versions before updating.
Analysis pending evidence review
HOL Guard separates source facts from reviewed analysis. See the methodology.
A CVSS score is not reported in the current record. Known-exploitation status makes exposure review time-sensitive. Treat this as a source-backed prioritization signal, not a statement about your environment.
Analysis status
Analysis pending evidence review
Factual feed record only; HOL analysis is not approved for indexing. Read the methodology.
The current feed maps paloaltonetworks/pan-os (generic), paloaltonetworks/pan-os (generic), paloaltonetworks/pan-os (generic), Palo Alto Networks/PAN-OS (generic). Check affected ranges and fixed versions before updating.
| Package | Affected range | Fixed version |
|---|---|---|
| paloaltonetworks/pan-osgeneric | >=10.2.0 <10.2.9-h1 | 10.2.9-h1 |
| paloaltonetworks/pan-osgeneric | >=11.0.0 <11.0.4-h1 | 11.0.4-h1 |
| paloaltonetworks/pan-osgeneric | >=11.1.0 <11.1.2-h3 | 11.1.2-h3 |
| Palo Alto Networks/PAN-OSgeneric | >=10.2.0 <10.2.9-h1 || >=11.0.0 <11.0.4-h1 || >=11.1.0 <11.1.2-h3 | 10.2.9-h1, 11.0.4-h1, 11.1.2-h3 |
Published upstream
Apr 12, 2024
Evidence: source:cvelist:source_dates:source-dates:recordSource modified
Oct 21, 2025
Evidence: source:cvelist:source_dates:source-dates:recordFirst seen by HOL
May 24, 2026
Added to CISA KEV
Apr 12, 2024
Evidence: source:kev:kev:kev:recordA command injection as a result of arbitrary file creation vulnerability in the GlobalProtect feature of Palo Alto Networks PAN-OS software for specific PAN-OS versions and distinct feature configurations may enable an unauthenticated attacker to execute arbitrary code with root privileges on the firewall. Cloud NGFW, Panorama appliances, and Prisma Access are not impacted by this vulnerability.
Quoted source text, attributed separately from HOL analysis.
A CVSS score is not reported in the current record. Known-exploitation status makes exposure review time-sensitive. Treat this as a source-backed prioritization signal, not a statement about your environment.
Analysis status
Analysis pending evidence review
Factual feed record only; HOL analysis is not approved for indexing. Read the methodology.
The current feed maps paloaltonetworks/pan-os (generic), paloaltonetworks/pan-os (generic), paloaltonetworks/pan-os (generic), Palo Alto Networks/PAN-OS (generic). Check affected ranges and fixed versions before updating.
| Package | Affected range | Fixed version |
|---|---|---|
| paloaltonetworks/pan-osgeneric | >=10.2.0 <10.2.9-h1 | 10.2.9-h1 |
| paloaltonetworks/pan-osgeneric | >=11.0.0 <11.0.4-h1 | 11.0.4-h1 |
| paloaltonetworks/pan-osgeneric | >=11.1.0 <11.1.2-h3 | 11.1.2-h3 |
| Palo Alto Networks/PAN-OSgeneric | >=10.2.0 <10.2.9-h1 || >=11.0.0 <11.0.4-h1 || >=11.1.0 <11.1.2-h3 | 10.2.9-h1, 11.0.4-h1, 11.1.2-h3 |
Published upstream
Apr 12, 2024
Evidence: source:cvelist:source_dates:source-dates:recordSource modified
Oct 21, 2025
Evidence: source:cvelist:source_dates:source-dates:recordFirst seen by HOL
May 24, 2026
Added to CISA KEV
Apr 12, 2024
Evidence: source:kev:kev:kev:recordA command injection as a result of arbitrary file creation vulnerability in the GlobalProtect feature of Palo Alto Networks PAN-OS software for specific PAN-OS versions and distinct feature configurations may enable an unauthenticated attacker to execute arbitrary code with root privileges on the firewall. Cloud NGFW, Panorama appliances, and Prisma Access are not impacted by this vulnerability.
Quoted source text, attributed separately from HOL analysis.