
Exploit für GlobalProtect CVE-2024-3400
Exploit für GlobalProtect CVE-2024-3400
Dieser Exploit zielt auf die ursprüngliche Schwachstelle ab, daher muss die Firewall eine verwundbare PAN-OS-Version ausführen und Telemetrie aktiviert haben.
Referenz: https://labs.watchtowr.com/palo-alto-putting-the-protecc-in-globalprotect-cve-2024-3400/
Beispiel für RCE mit Remote-Connect-Back-Shell:

Auf dem Remote-Host:
