Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

PRP: PAN-OS Firewall RCE #468

Open
secureness opened this issue Apr 13, 2024 · 1 comment
Open

PRP: PAN-OS Firewall RCE #468

secureness opened this issue Apr 13, 2024 · 1 comment
Assignees

Comments

@secureness
Copy link
Contributor

PAN-OS Firewall is a popular firewall with more than 40K instances on the internet.
the exploit is easy to trigger it is a simple post request.
due to active exploitation, I think it is better to let me write a plugin for this vulnerability as soon as possible.

https://www.volexity.com/blog/2024/04/12/zero-day-exploitation-of-unauthenticated-remote-code-execution-vulnerability-in-globalprotect-cve-2024-3400/
https://socradar.io/critical-os-command-injection-vulnerability-in-palo-altos-globalprotect-gateway-cve-2024-3400-the-patch-is-not-available-yet/

@maoning
Copy link
Collaborator

maoning commented Apr 18, 2024

Hi @secureness,

Thanks for your request! This vulnerability is in scope for the reward program. Please submit our participation form and you can start working on the development.

Please keep in mind that the Tsunami Scanner Team will only be able to work at one issue at a time for each participant so please hold on the implementation work for any other requests you might have.

Thanks!

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Projects
None yet
Development

No branches or pull requests

2 participants