Why Security Appliances Are Not Enough for Enterprises: Insights from CVE-2024-3400 In the wake of the discovery of a critical CVE (Common Vulnerabilities and Exposures), CVE-2024-3400, within Palo Alto Networks’ GlobalProtect feature of PAN-OS software, it’s become increasingly evident that enterprises must approach their infrastructure security with a cautious perspective. While appliances designed to safeguard organizations can inadvertently serve as entry points for threat actors, employing red team strategies can fortify defenses by proactively identifying and addressing vulnerabilities before they are exploited. What is CVE-2024-3400? The recently disclosed CVE affects Gateways within GlobalProtect, Palo Alto’s trusted secure remote access solution. Utilizing GlobalProtect, remote users securely connect to internal resources on the WAN or external resources on the Internet via Palo Alto NGFWs serving as GlobalProtect Gateways. Palo Alto warns that a critical vulnerability in its PAN-OS software enables threat actors to execute code on affected GlobalProtect gateways. Identified as CVE-2024-3400, this flaw carries the highest possible severity rating, a CVSS score of 10.0. “A command injection vulnerability in the GlobalProtect feature of Palo Alto Networks PAN-OS software for specific PAN-OS versions and distinct feature configurations may enable an unauthenticated attacker to execute arbitrary code with root privileges on the firewall,” writes the company in a recently published advisory. The advisory notes the affected version: PAN-OS versions earlier than 11.1.2-h3, 11.0.4-h1 and 10.2.9-h1. Updates to address this issue are scheduled for release on April 14, 2024. The vulnerability only affects firewalls configured with the GlobalProtect gateway and device telemetry settings. While specific details about the attacks and the identities of the perpetrators remain undisclosed, Palo Alto Networks has confirmed a few instances of attacks exploiting this vulnerability. The company recommends Threat Prevention subscribers activate Threat ID 95187 as a protective measure. Continue reading: https://lnkd.in/ggfcRrwz
SASE Experts
Information Technology & Services
Denver, CO 8,549 followers
Independent experts advising enterprises worldwide on secure SD-WAN & SASE selection for WAN transformation.
About us
“There are so many apparent SASE and SD-WAN options in the market. They may seem to offer the same capabilities…but they don’t. You really need an expert to advise you so you make the right decision for your enterprise” At SD-WAN Experts, we specialize in designing, sourcing, and launching secure SD-WAN networks that meet your evolving business needs. We assist you in building the right solution today, with an upgrade path to tomorrow. Whether you need service domestically, or in Asia, Europe, North or South America, SD-WAN-Experts can provide the best solutions and manage the implementation for you. We blend experience and expertise. You benefit from our independence. Single point of contact. Cost-effective and responsive. If you would like to have more information, do not hesitate to call or email us. You will be immediately reach a friendly, knowledgeable and experienced IT professional. Our initial consultations are free. Make an appointment at https://www.sd-wan-experts.com/schedule-meeting/
- Website
-
https://www.sase-experts.com
External link for SASE Experts
- Industry
- Information Technology & Services
- Company size
- 11-50 employees
- Headquarters
- Denver, CO
- Type
- Privately Held
- Founded
- 2007
- Specialties
- SD-WAN, WAN Optimization, Network Security, WAN Transformation, Wide Area Networks, Security and Regulatory Compliance , and SASE
Locations
-
Primary
1966 S Humboldt St
Denver, CO 80210, US
Employees at SASE Experts
-
Steve Garson
⭐️President SASE -Experts⭐️NetworkWorld Author: Ask The WAN Expert⭐️ ⭐️SD-WAN Thought Leader⭐️ Speaker
-
حسین اصلانی
Account Manager at SD-WAN Experts
-
Lipika Parvin
Business Professional at SD-WAN Experts
-
Wan. Ayub Wan ariffin
Wan ayub bin haji wan ariffin at SD-WAN Experts