
The U.S. CISA added the CVE-2024-3400 Palo Alto Networks PAN-OS Command Injection vulnerability to its Known Exploited Vulnerabilities catalog.
The vulnerability is a critical command injection in Palo Alto Networks PAN-OS software. An unauthenticated attacker can exploit the flaw to execute arbitrary code with root privileges on affected firewalls. This flaw impacts PAN-OS 10.2, PAN-OS 11.0, and PAN-OS 11.1 firewalls configured with GlobalProtect gateway or GlobalProtect portal (or both) and device telemetry enabled.
Palo Alto Networks and Unit 42 are investigating the activity related to CVE-2024-3400 PAN-OS flaw and discovered that threat actors have been exploiting it since March 26, 2024.
The researchers are tracking this cluster of activity conducted by an unknown threat actor under the name Operation MidnightEclipse.
Upon exploiting the flaw, the threat actor was observed creating a cronjob that would run every minute to access commands hosted on an external server that would execute via bash.
The researchers were unable to access the commands executed by the attackers. However, they believe threat actors attempted to deploy a second Python-based backdoor on vulnerable devices.
CISA orders federal agencies to fix this vulnerability by April 19, 2024.
Meanwhile, Palo Alto Networks has released patches for a critical 0-day vulnerability that threatened to leave firewalls exposed to cyberattacks.


