kevmap

Coverage › CVE-2024-3400

CVE-2024-3400 Unmapped

Palo Alto Networks PAN-OS Command Injection Vulnerability

Vendor / product
Palo Alto Networks — PAN-OS
Description (CISA)
Palo Alto Networks PAN-OS GlobalProtect feature contains a command injection vulnerability that allows an unauthenticated attacker to execute commands with root privileges on the firewall.
Added to KEV
2024-04-12
Due date
2024-04-19
Required action
Apply mitigations per vendor instructions as they become available. Otherwise, users with vulnerable versions of affected devices should enable Threat Prevention IDs available from the vendor. See the vendor bulletin for more details and a patch release schedule.
Known ransomware use
Known
CWE
CWE-20, CWE-77
CISA notes
https://security.paloaltonetworks.com/CVE-2024-3400
https://nvd.nist.gov/vuln/detail/CVE-2024-3400
Elsewhere
cve.org · NVD · CISA KEV · JSON

ATT&CK techniques

No public source states how this vulnerability is exploited in ATT&CK terms.

The only authoritative CVE → ATT&CK mapping in the open — CTID's Mappings Explorer, pinned to a KEV snapshot of 2025-07-28 and ATT&CK 16.1 — does not include CVE-2024-3400. CISA's catalogue carries no technique field. kevmap does not infer techniques from the CWE (CWE-20, CWE-77) — here is why — and does not guess.

This page will change state automatically if a mapping is published. What is shown above is everything CISA publishes about the entry.

Sigma rules tagged with this CVE

2 rules in SigmaHQ carry the tag cve.2024-3400. These are shown as detection content for the CVE itself. Their ATT&CK tags are deliberately not rendered here: a rule author's tag is not an authoritative statement of how the vulnerability is exploited, and this page does not show techniques for unmapped entries.

Author: Andreas Braathen (mnemonic.io) · 2024-04-25 · logsource: product=paloalto category=file_event service=globalprotect · bcd95697-e3e7-4c6f-8584-8e3503e6929f
Detects suspicious file creations in the Palo Alto Networks PAN-OS' parent telemetry folder, which are processed by the vulnerable 'dt_curl' script if device telemetry is enabled. As said script overrides the shell-subprocess restriction, arbitrary command execution may occur by carefully crafting filenames that are escaped through this function.
CVE tags: CVE-2024-3400
Author: Nasreddine Bencherchali (Nextron Systems) · 2024-04-18 (modified 2025-11-22) · logsource: product=paloalto category=appliance service=globalprotect · f130a5f1-73ba-42f0-bf1e-b66a8361cb8f
Detects potential exploitation attempts of CVE-2024-3400 - an OS command injection in Palo Alto GlobalProtect. This detection looks for suspicious strings that indicate a potential directory traversal attempt or command injection.
CVE tags: CVE-2024-3400