HC3-TLP Clear Sector Alert: Palo Alto Networks Firewalls

Executive Summary

On April 12, 2024, Palo Alto Networks has warned of a command injection vulnerability (CVE-2024-3400) impacting its firewalls. The vulnerability can be exploited in an automated manner, and the company recommends that customers apply temporary mitigations. Palo Alto Networks is aware of a limited number of attacks utilizing this vulnerability. HC3 recommends that all users review the security alert released by Palo Alto and apply any mitigations or workarounds to prevent serious damage in the Healthcare and Public Health (HPH) sector.

For help with Cybersecurity and Risk Advisory Services exclusively for AHA members, contact:

John Riggi

National Advisor for Cybersecurity and Risk, AHA

jriggi@aha.org

(O) +1 202 626 2272