Security Research

CVE-2024-3400 Palo Alto GlobalProtect Command Injection: a CVSS 10.0 critical chain attack

#Vulnerability Analysis#Code Audit#Network Attack
Dark dossier of PAN-OS GlobalProtect edge-device compromise

The Palo Alto GlobalProtect command injection scored a perfect 10.0 on CVSS. An unauthenticated attacker sends a crafted request to run arbitrary commands on the firewall and writes a cron job for persistence.

Unlock to view this content.