Listen to this Post
CVE-2024-3400 is a critical command injection vulnerability in the GlobalProtect feature of Palo Alto Networks PAN-OS software. The vulnerability allows an unauthenticated remote attacker to execute arbitrary code with root privileges on the affected firewall. The flaw exists in the device telemetry feature, where user-controlled input from a crafted session cookie is passed to a shell context without proper sanitization. Exploitation requires that either GlobalProtect Portal or GlobalProtect Gateway be enabled. The vulnerability was discovered by Volexity and was exploited in the wild as a zero-day. The CVSS score is 10.0, indicating maximum severity. The attack chain involves an arbitrary file creation vulnerability and a command injection vulnerability. The crafted session cookie contains a telemetry-related session ID that is processed by the vulnerable code path. The attacker can then execute arbitrary commands with root privileges, leading to full compromise of the firewall. The vulnerability affects PAN-OS versions 10.2, 11.0, and 11.1. Patches were released in versions 10.2.9-h1, 11.0.4-h1, and 11.1.2-h3. The exploitation allows for reverse shell creation, downloading of further tools, and lateral movement within the network. The vulnerability is particularly dangerous because the affected components are typically internet-facing. The lack of authentication required makes it easily exploitable by remote attackers. The command injection occurs because the session ID is not properly sanitized before being used in a shell command. The attacker can inject arbitrary commands by manipulating the session cookie. The vulnerability was actively exploited by threat actors, including UTA0218, who deployed the UPSTYLE backdoor. The backdoor is a Python script persisted through a crontab entry, providing an interactive command and control channel. The attacker can exfiltrate configuration files and credentials, and pivot to internal network resources. The vulnerability highlights the risks of unsanitized user input in security-critical components. Organizations are urged to apply patches immediately or implement mitigations such as disabling device telemetry, though this is not fully effective. The CVE was added to CISA’s Known Exploited Vulnerabilities catalog. The timeline from discovery to patch was rapid, with patches released within days. The vulnerability serves as a reminder of the importance of timely patching and monitoring for indicators of compromise.
DailyCVE Form:
Platform: PAN-OS
Version: 10.2, 11.0, 11.1
Vulnerability: Command Injection
Severity: Critical
date: 2024-04-12
Prediction: 2024-04-14
What Undercode Say:
Analytics
Bash command to check GlobalProtect configuration:
show global-protect gateway show global-protect portal
C code for SUID binary:
include <stdio.h>
include <stdlib.h>
include <unistd.h>
// Compile with /usr/bin/x86_64-linux-musl-gcc -static -o root root.c
int main (int argc, char argv[]) {
if (argc < 2) {
fprintf(stdout, "usage: %s command\n", argv[bash]);
return 1;
}
setuid(0);
setgid(0);
setgroups(0, NULL);
execl("/bin/sh", "sh", "-c", argv[bash], (char )NULL);
perror("execl failed");
return EXIT_FAILURE;
}
Example curl command to exploit crafted cookie:
curl -H "Cookie: SESSID=../../../../var/appweb/htdocs/unauth/php/shell.php" http://target/global-protect/login.esp
Exploit: (Educational Purposes!)
The exploit chain begins with an arbitrary file creation vulnerability in the GlobalProtect web server. An attacker can create a malicious file on the device by sending a crafted request. This file is then leveraged to trigger the command injection vulnerability in the device telemetry feature. The attacker crafts a session cookie containing a telemetry-related session ID that is passed to a shell context without sanitization. By injecting shell metacharacters into the session ID, the attacker can execute arbitrary commands with root privileges. The exploit can be triggered remotely without authentication, allowing the attacker to gain full control of the firewall. The attacker can then create a reverse shell, download additional tools, and exfiltrate sensitive data such as the running configuration. The UPSTYLE backdoor is deployed to maintain persistent access, using a crontab entry to execute a Python script that polls a file path for commands.
Protection
Apply the latest PAN-OS hotfixes: 10.2.9-h1, 11.0.4-h1, or 11.1.2-h3. If patching is not immediately possible, disable device telemetry as an interim mitigation, though this may not fully close the vulnerable code path. Monitor for indicators of compromise, such as unexpected files in /var/appweb/htdocs/unauth/php or unusual crontab entries. Restrict access to GlobalProtect portals and gateways where feasible. Enable logging and alerts for suspicious session cookie values. Follow CISA’s remediation guidance and verify system integrity after patching.
Impact
Successful exploitation allows an unauthenticated remote attacker to execute arbitrary code with root privileges on the firewall. This leads to complete compromise of the device, enabling the attacker to create reverse shells, harvest configuration and credentials, and pivot laterally into the internal network. The attacker can exfiltrate sensitive data, including running_config.xml and credential stores. The firewall’s role as a security perimeter device means its compromise can expose the entire protected network. The vulnerability has been exploited in the wild by threat actors, including nation-state-linked groups, to maintain persistent access through the UPSTYLE backdoor.
🎯Let’s Practice Exploiting & Learn Patching For Free:
🎓 Live Courses & Certifications:
Join Undercode Academy for Verified Certifications
🚀 Request a Custom Project:
Secure, high-velocity infrastructure and disruptive technological engineering. Contact our engineering team for high-tier development and proprietary systems:
[email protected]
💎 Smart Architecture | 🛡️ Secure by Design | ⭐ Trusted by Thousands
Sources:
Reported By: github.com
Extra Source Hub:
Undercode

