A command injection as a result of arbitrary file creation vulnerability in the GlobalProtect feature of Palo Alto Networks PAN-OS software for specific PAN-OS versions and distinct feature configurations may enable an unauthenticated attacker to execute arbitrary code with root privileges on the firewall. Cloud NGFW, Panorama appliances, and Prisma Access are not impacted by this vulnerability.
https://cloud.google.com/blog/topics/threat-intelligence/ransomware-ttps-shifting-threat-landscape/
https://www.greynoise.io/blog/unmasking-cisas-hidden-kev-ransomware-updates
https://isc.sans.edu/diary/rss/32328
https://thehackernews.com/2025/09/chinese-hackers-rednovember-target.html
https://www.darkreading.com/threat-intelligence/chinese-apt-oss-pocs-spy-countries
https://www.theregister.com/2025/08/28/china_salt_typhoon_alert/
https://www.securityweek.com/chinas-salt-typhoon-hacked-critical-infrastructure-globally-for-years/
https://www.infosecurity-magazine.com/news/chinese-tech-firms-salt-typhoon/
https://thehackernews.com/2025/08/salt-typhoon-exploits-cisco-ivanti-palo.html
https://www.securityweek.com/chinas-salt-typhoon-hacked-us-national-guard/
https://cyberscoop.com/sonicwall-exploited-vulnerabilities-surge/
https://www.theregister.com/2025/03/05/china_silk_typhoon_update/
https://www.microsoft.com/en-us/security/blog/2025/03/05/silk-typhoon-targeting-it-supply-chain/
https://www.darkreading.com/remote-workforce/china-silk-typhoon-it-supply-chain-attacks
https://thehackernews.com/2025/03/china-linked-silk-typhoon-expands-cyber.html
https://securelist.com/vulnerabilities-and-exploits-in-q4-2024/115761/
https://cyberscoop.com/edge-device-vulnerabilities-fuel-attack-sprees/
https://thehackernews.com/2025/02/ransomhub-becomes-2024s-top-ransomware.html
https://www.group-ib.com/blog/ransomhub-never-sleeps-episode-1/
https://www.cisa.gov/news-events/cybersecurity-advisories/aa24-241a
https://securelist.com/vulnerability-exploit-report-q2-2024/113455/
https://www.tenable.com/blog/edge-infrastructure-under-siege
https://www.tenable.com/blog/frequently-asked-questions-about-iranian-cyber-operations
https://www.tenable.com/blog/verizon-2025-dbir-tenable-research-collaboration
https://github.com/taravindan87-kavi/CVSS-X-where-X-stands-for-Context-or-eXposure-
https://github.com/raz0rgirl/cve-notifier
https://github.com/PwnedBytes0x1/cveye
https://github.com/wong-hau-pepelu/freshk3v
https://github.com/chengbochuan3/CVE-Network-Device
https://github.com/nkoziel/cve-to-detection-rule
https://github.com/mtayeb89/AI-Threat-Intelligence-Assistant
https://github.com/threadlinqs-cmd/intelthreadlinqs-mcp
https://github.com/HaakimSec/zero2shell-50
https://github.com/crimson-crawler/python-sdk
https://github.com/crimson-crawler/typescript-sdk
https://github.com/crimson-crawler/ccc
https://github.com/ctkrug/cve-radar
https://github.com/rohanrajnist/vuln-intel-mcp
https://github.com/iamnikitakhare/Cybersecurity-RAG
https://github.com/Cyber-protect/CVE-Assessor
https://github.com/Lanexus/cve-scanner
https://github.com/cognis-digital/cveintel
https://github.com/AllainDB/edge-exposure-auditor
https://github.com/rozetyp/vuln-intel-mcp
https://github.com/omobolajiadeyan/vulngpt
https://github.com/kvsaurav/CVE-prioritization-
https://github.com/Aniroodh-cse/Team-2_report_builder
https://github.com/nguyenminhduc3103/CVE_TOOL_SIGMARULE
https://github.com/Nikki-the-Parcel/Global-Protect_VPN_Vuln
https://github.com/ZimCanIT/nvd-cve-lookup-mcp-server
https://github.com/rdintel/rdintel-mcp
https://github.com/HishamAl-Hamdi/cve-hunter
https://github.com/JeneelPanchalV/securellm
https://github.com/EJAtwood/mcp-vulnerability-server
https://github.com/sreenidhi-n/socrates
https://github.com/SimoesCTT/CTT-enhanced-Dirty-Frag-exploit
https://github.com/unknownCyberEnthusiast/cve-cti
https://github.com/arunpushkar-dev/VulnPriority
https://github.com/wfarouk2023/MCP-CVE-server
https://github.com/oadeyan/vulngpt
https://github.com/wa6n3r/CVE-2024-3400
https://github.com/Csindu03/cf_ai_threat_intel
https://github.com/Zedocun/PAN-OS-CVE-2024-3400-Command-Injection-Investigation
https://github.com/mukul975/cve-mcp-server
https://github.com/Vikrant892/threat-lens
https://github.com/kholcomb/threatbridge
https://github.com/SimoesCTT/-CTT-PAN-OS-EXPLOIT-CVE-2024-340
https://github.com/splitfireai-hue/sentinelx402
https://github.com/UPinar/contrastapi
https://github.com/zer0trace1/satei
https://github.com/hermestoola/bb-hunter-pro
https://github.com/chiranths09/Syntecxhub_Project_Vulnerability-CVE-Scanner
https://github.com/badchars/cve-mcp
https://github.com/nethoundsh/shogunhound
https://github.com/TI-Mindmap-HUB-Org/ti-mindmap-hub-mcp
https://github.com/L0gic77/cve-watchlist
https://github.com/splinterlabs/osint-agent-public
https://github.com/CipherX9FSecurity/CVE-Exploitation-Analysis
https://github.com/lhassa8/veridano-skill
https://github.com/nanwinata/CVE-2025-55182-Scanner
https://github.com/Yafiah-Darwesh/cs50-cyber-paloalto-oauth
https://github.com/Cyb3rTim/Cyber-Threat-Intelligence-Dashboard
https://github.com/shreyxploit/ThreatLens
https://github.com/ozanunal0/viper
https://github.com/Rohith-Reddy-Y/Zero-Day-Vulnerability-Exploitation-Detection-Tool
https://github.com/CyprianAtsyor/letsdefend-cve2024-3400-case-study
https://github.com/XiaomingX/CVE-2024-3400-poc
https://github.com/nanwinata/CVE-2024-3400
Published: 2024-04-12
Updated: 2025-11-04
Known Exploited Vulnerability (KEV)
Base Score: 10
Vector: CVSS2#AV:N/AC:L/Au:N/C:C/I:C/A:C
Severity: Critical
Base Score: 10
Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H
Severity: Critical
Base Score: 10
Vector: CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H
Severity: Critical
EPSS: 0.99999
Tenable Research has classified this CVE under the following Vulnerability Watch classification, which includes active and historical (inactive) classifications. You can learn more about these classifications on our blog.
Vulnerability of Concern