Remove Access Point Remove Cookie Remove DNS
article thumbnail

CVE-2024-3400: Critical Palo Alto PAN-OS Command Injection Vulnerability Exploited by Sysrv Botnet’s XMRig Malware

CATO Networks

The vulnerability is in the SESSID cookie value, which creates a new file for every session as root. Click for full-size] [Click for full-size] We also ran the malware in a controlled environment and saw it periodically sends DNS requests to www[.]dblikes[.]top. For a detailed vulnerability analysis, visit the Attackerkb blog.

SASE 52