FortiSIEM Discussions
darayun
New Contributor

Tuning FortiSIEM Rule: CVE-2024-3400 PAN-OS: OS Command Injection Vulnerability in GlobalProtect

Dear Respective Team,

 

Do you have any tip or technic for fine tuning the fortiSIEM rules/incident alert related to CVE-2024-3400 PAN-OS: OS Command Injection Vulnerability in GlobalProtect?

 

https://security.paloaltonetworks.com/CVE-2024-3400

 

Best Regards,

Dara

2 REPLIES 2
FSM_FTNT
Staff
Staff

Hi Dara,

 

We have released content update 607 to help detect this, primarily using FortiGate and FortiClient signature detections. Please ensure that you download the latest content and review.

 

https://help.fortinet.com/fsiem/7-1-5/Online-Help/HTML5_Help/content_updates.htm#Content12

darayun
New Contributor

Dear FMS-FTNT,

 

I well received it, and I thank you so much for your fast response. Now, I am testing the rule.

 

Best Regards,

Dara