Nothing to apply yet — a PAN-OS flaw listed before any patch existed
For the command injection flaw in Palo Alto Networks PAN-OS, CISA called for mitigations to be applied as they became available. In place of an update, enabling the vendor threat prevention identifiers was named as what to do meanwhile.
Key facts
- CVE IDCVE-2024-3400
- Affected (vendor / product)Palo Alto Networks PAN-OS
- CWECWE-20, CWE-77
- ExploitationListed in CISA KEV (exploitation confirmed); also confirmed used in ransomware
- Remediation due2024-04-19 (U.S. federal civilian agencies, BOD 22-01)
Key points
- CVE-2024-3400 is a command injection flaw in the PAN-OS GlobalProtect feature, where someone who has not authenticated can get commands to run on the firewall at root.
- The required action is that mitigations be put on as the vendor supplies them.
- Otherwise, users of vulnerable versions should enable the threat prevention identifiers the vendor supplies.
- The entry directs readers to the vendor bulletin for details and a patch release schedule, indicating no fix was published at listing.
- Listed 12 April 2024 with a due date of 19 April, a window of seven days; of the 1,579 entries without an article this site holds as of 2026-09-05, 317 (20.1%) are known in ransomware use.
1When apply the update cannot be written
The two entries so far assumed an update existed. This one does not. At the moment of listing, no patch had been published. The instruction takes a conditional form, as they become available, and names something else to do in the meantime.
2The shape of the instruction
That a patch release schedule is mentioned at all is unusual. Catalog entries ordinarily set a due date on the assumption that a fix exists. Here the existence of the fix is itself spoken of in the future tense.
3Exploitation first, fix second
To be listed in the catalog is to have already been exploited. The attack arrives regardless of whether a fix does. The instruction therefore has no choice but to say what to do while the fix is awaited.
4What was named instead
What is named is enabling the threat prevention identifiers the vendor supplies. That does not remove the flaw; it brings a mechanism to bear that detects and stops known attack patterns. Not closing the hole, but stopping what comes through it. Until a fix exists, that is the level the instruction asks for.
The next article takes up an entry that asked agencies to fix the flaw and then determine whether they had already been compromised, and report it.
Why it matters
Because the catalog collects vulnerabilities confirmed to have been exploited, the existence of a fix is not a precondition. Where the attack comes first and the fix later, the instruction takes a future tense and has to name something else for the interval. What it asks in that gap is not the removal of the flaw but the stopping of what passes through it.
FAQ
Why is the instruction conditional on availability?
What does enabling threat prevention identifiers do?
Can something be listed with no fix available?
Sources (primary)
This article is an independent organization based on the U.S. official data below. Always verify the exact, latest details and applicability with the official and vendor sources.
- CISA KEV Catalog (known exploited list)
- NVD (CVE details / CVSS)
- Vendor / reference advisory
- This product uses data from the NVD API but is not endorsed or certified by the NVD. KEV data is CC0 (public domain).