Remove Access Point Remove Cookie Remove IP Address
article thumbnail

CVE-2024-3400: Critical Palo Alto PAN-OS Command Injection Vulnerability Exploited by Sysrv Botnet’s XMRig Malware

CATO Networks

The vulnerability is in the SESSID cookie value, which creates a new file for every session as root. An investigation of the IP address reveals that it is associated with a known Sysrv Botnet. It is found in multiple versions of PAN-OS, the operating system that powers Palo Altos firewall appliances.

SASE 52