Security researchers at SANS ISC detected a single source IP address (141.98.82.26) systematically issuing crafted POST and GET requests against the GlobalProtect file-upload endpoint, underscoring the ease of automation and the urgency of patching impacted systems.
Researchers observed two straightforward steps leveraged by attackers:
/ssl-vpn/hipreport.esp, forcing the creation of a session file within the GlobalProtect directory.These actions allow adversaries to confirm arbitrary file placement.
In a real-world attack, this would be chained to execute OS commands, enabling root-level control over the firewall.
| CVE ID | Description | CVSS 4.0 Score | Affected PAN-OS Versions |
|---|---|---|---|
| CVE-2024-3400 | Arbitrary file creation leading to OS command injection | 10.0 | 10.2 (<10.2.0-h3 to <10.2.9-h1) |
| 11.0 (<11.0.0-h3 to <11.0.4-h1) | |||
| 11.1 (<11.1.0-h3 to <11.1.2-h3) |
This flaw affects PAN-OS versions configured with a GlobalProtect portal or gateway. Cloud NGFW, Panorama, and Prisma Access are not vulnerable.
Palo Alto Networks has assigned a perfect CVSS 4.0 score of 10.0 and an “HIGHEST” urgency rating.
Public proof-of-concept exploits and persistence techniques have already surfaced, heightening risk to unpatched environments.
Although no widespread, confirmed in-the-wild breaches have been reported beyond proof-of-concept, the vulnerability’s network-accessible nature and lack of authentication requirement make it a prime target for opportunistic operators and botnets.
Recommended Actions:
hipreport.esp and /global-protect/portal/images/, and alert on unusual user-agent strings or repeated 403/404 response patterns.With scanning activity surging and exploit code public, organizations must prioritize continuous monitoring, timely patching, and deployment of threat prevention signatures to thwart potential full-system compromise.
Failure to address CVE-2024-3400 immediately could result in root-level control of critical network security infrastructure.
Find this Story Interesting! Follow us on Google News, LinkedIn, and X to Get More Instant Updates
The post Hackers Actively Scanning for PAN-OS GlobalProtect Vulnerability appeared first on Cyber Security News.
Today, Pokémon Winds and Pokémon Waves were announced during a Pokémon Presents, showing off a…
Samsung's newest smartphones - the Galaxy S26, S26+, and S26 Ultra - were recently announced…
LEGO and Pokémon were my childhood (well, those and TMNT, but that’s for another time).…
From @Sam Nichols: Sunny, warm, and windy this weekend
From @Sam Nichols: Sunny, warm, and windy this weekend
From @Sam Nichols: Sunny, warm, and windy this weekend
This website uses cookies.