Exploited Known exploited (KEV) Ransomware use CVE-2024-3400

Nothing to apply yet — a PAN-OS flaw listed before any patch existed

Palo Alto Networks PAN-OS Added to KEV Apr 12, 2024 Federal remediation due 2024-04-19

For the command injection flaw in Palo Alto Networks PAN-OS, CISA called for mitigations to be applied as they became available. In place of an update, enabling the vendor threat prevention identifiers was named as what to do meanwhile.

Key facts

  • CVE IDCVE-2024-3400
  • Affected (vendor / product)Palo Alto Networks PAN-OS
  • CWECWE-20, CWE-77
  • ExploitationListed in CISA KEV (exploitation confirmed); also confirmed used in ransomware
  • Remediation due2024-04-19 (U.S. federal civilian agencies, BOD 22-01)

Key points

  • CVE-2024-3400 is a command injection flaw in the PAN-OS GlobalProtect feature, where someone who has not authenticated can get commands to run on the firewall at root.
  • The required action is that mitigations be put on as the vendor supplies them.
  • Otherwise, users of vulnerable versions should enable the threat prevention identifiers the vendor supplies.
  • The entry directs readers to the vendor bulletin for details and a patch release schedule, indicating no fix was published at listing.
  • Listed 12 April 2024 with a due date of 19 April, a window of seven days; of the 1,579 entries without an article this site holds as of 2026-09-05, 317 (20.1%) are known in ransomware use.

1When apply the update cannot be written

The two entries so far assumed an update existed. This one does not. At the moment of listing, no patch had been published. The instruction takes a conditional form, as they become available, and names something else to do in the meantime.

2The shape of the instruction

The aspectAn entry where an update existsThis entry, PAN-OS
Main directionApply updates per vendor instructionsApply mitigations per vendor instructions as they become available
What to do until thenUsually unmentionedUsers of vulnerable versions should enable the threat prevention identifiers
Where to lookThe vendor bulletin, for details and a patch release schedule
AssumptionA fix already existsA fix does not yet exist

That a patch release schedule is mentioned at all is unusual. Catalog entries ordinarily set a due date on the assumption that a fix exists. Here the existence of the fix is itself spoken of in the future tense.

3Exploitation first, fix second

Of the 1,695 records this site holds as of 2026-09-05, those without an article1,579All are vulnerabilities confirmed to have been exploited
Of those, entries recorded as known in ransomware use31720.1%
The window hereSeven daysListed 12 April 2024, due 19 April 2024

To be listed in the catalog is to have already been exploited. The attack arrives regardless of whether a fix does. The instruction therefore has no choice but to say what to do while the fix is awaited.

4What was named instead

What is named is enabling the threat prevention identifiers the vendor supplies. That does not remove the flaw; it brings a mechanism to bear that detects and stops known attack patterns. Not closing the hole, but stopping what comes through it. Until a fix exists, that is the level the instruction asks for.

The next article takes up an entry that asked agencies to fix the flaw and then determine whether they had already been compromised, and report it.

Why it matters

Because the catalog collects vulnerabilities confirmed to have been exploited, the existence of a fix is not a precondition. Where the attack comes first and the fix later, the instruction takes a future tense and has to name something else for the interval. What it asks in that gap is not the removal of the flaw but the stopping of what passes through it.

FAQ

Why is the instruction conditional on availability?
Because it sends readers to the vendor bulletin for the particulars and for when a patch might arrive, indicating no fix existed when the entry was made.
What does enabling threat prevention identifiers do?
It does not remove the flaw but brings to bear a mechanism that detects and blocks known attack patterns.
Can something be listed with no fix available?
Yes. The catalog collects vulnerabilities confirmed to have been exploited, independently of whether a fix exists.

Sources (primary)

This article is an independent organization based on the U.S. official data below. Always verify the exact, latest details and applicability with the official and vendor sources.

#Vulnerabilities#KEV#CISA#United States#Cybersecurity
Disclaimer: This site independently summarizes and classifies information based on official data sources. Always verify the latest and accurate information with the official sources. Content on finance, health, legal, and security is information, not advice. This site is not an official website of the U.S. government.