April 12, 2024, 5:19 p.m. | Scott Caveza

Cyber Exposure Alerts www.tenable.com

A critical severity command injection vulnerability in Palo Alto Networks PAN-OS has been exploited in limited targeted attacks. While a fix is not yet available, patches are expected to be released on April 14 and mitigation steps are available.

Background

On April 12, Palo Alto Networks released a security advisory for a critical command injection vulnerability affecting PAN-OS, the custom operating system (OS) Palo Alto Networks (PAN) uses in their next-generation firewalls.

CVEDescriptionCVSSv3SeverityCVE-2024-3400Command Injection Vulnerability in …

alto april attacks command command injection critical cve cve-2024 cve-2024-3400 exploited fix gateway globalprotect injection in the wild mitigation networks palo palo alto palo alto networks palo alto networks pan-os pan pan-os patches severity targeted attacks vulnerability zero-day zero-day vulnerability

More from www.tenable.com / Cyber Exposure Alerts

Information Security Engineers

@ D. E. Shaw Research | New York City

Technology Security Analyst

@ Halton Region | Oakville, Ontario, Canada

Senior Cyber Security Analyst

@ Valley Water | San Jose, CA

Sr. Staff Firmware Engineer – Networking & Firewall

@ Axiado | Bengaluru, India

Compliance Architect / Product Security Sr. Engineer/Expert (f/m/d)

@ SAP | Walldorf, DE, 69190

SAP Security Administrator

@ FARO Technologies | EMEA-Portugal