{"api_version":"1","generated_at":"2026-07-23T19:12:56+00:00","cve":"CVE-2020-1976","urls":{"html":"https://cve.report/CVE-2020-1976","api":"https://cve.report/api/cve/CVE-2020-1976.json","docs":"https://cve.report/api","cve_org":"https://www.cve.org/CVERecord?id=CVE-2020-1976","nvd":"https://nvd.nist.gov/vuln/detail/CVE-2020-1976"},"summary":{"title":"CVE-2020-1976","description":"A denial-of-service (DoS) vulnerability in Palo Alto Networks GlobalProtect software running on Mac OS allows authenticated local users to cause the Mac OS kernel to hang or crash. This issue affects GlobalProtect 5.0.5 and earlier versions of GlobalProtect 5.0 on Mac OS.","state":"PUBLIC","assigner":"psirt@paloaltonetworks.com","published_at":"2020-02-12 23:15:00","updated_at":"2020-05-04 14:14:00"},"problem_types":["CWE-20"],"metrics":[],"references":[{"url":"https://security.paloaltonetworks.com/CVE-2020-1976","name":"N/A","refsource":"CONFIRM","tags":["Vendor Advisory"],"title":"CVE-2020-1976 GlobalProtect on MacOS: Local denial-of-service (DoS) vulnerability.","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"https://www.cve.org/CVERecord?id=CVE-2020-1976","name":"CVE Program record","refsource":"CVE.ORG","tags":["canonical"]},{"url":"https://nvd.nist.gov/vuln/detail/CVE-2020-1976","name":"NVD vulnerability detail","refsource":"NVD","tags":["canonical","analysis"]}],"affected":[],"timeline":[],"solutions":[],"workarounds":[],"exploits":[],"credits":[{"source":"LEGACY","value":"This issue was discovered during a security test performed in collaboration with IOActive.","lang":""}],"nvd_cpes":[{"cve_year":"2020","cve_id":"1976","vulnerable":"1","versionEndIncluding":"5.0.5","cpe1":"cpe","cpe2":"2.3","cpe3":"a","cpe4":"paloaltonetworks","cpe5":"globalprotect","cpe6":"*","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"macos","cpe12":"*","cpe13":"*"}],"vendor_comments":[],"enrichments":{"kev":null,"epss":null,"legacy_qids":[]},"source_records":{"cve_program":{"CVE_data_meta":{"ASSIGNER":"psirt@paloaltonetworks.com","DATE_PUBLIC":"2020-02-12T17:00:00.000Z","ID":"CVE-2020-1976","STATE":"PUBLIC","TITLE":"GlobalProtect on MacOS: Local denial-of-service (DoS) vulnerability."},"affects":{"vendor":{"vendor_data":[{"product":{"product_data":[{"product_name":"GlobalProtect","version":{"version_data":[{"platform":"Mac OS","version_affected":"<=","version_name":"5.0","version_value":"5.0.5"},{"platform":"Mac OS","version_affected":"!>=","version_name":"5.0","version_value":"5.0.6"}]}}]},"vendor_name":"Palo Alto Networks"}]}},"credit":[{"lang":"eng","value":"This issue was discovered during a security test performed in collaboration with IOActive."}],"data_format":"MITRE","data_type":"CVE","data_version":"4.0","description":{"description_data":[{"lang":"eng","value":"A denial-of-service (DoS) vulnerability in Palo Alto Networks GlobalProtect software running on Mac OS allows authenticated local users to cause the Mac OS kernel to hang or crash. This issue affects GlobalProtect 5.0.5 and earlier versions of GlobalProtect 5.0 on Mac OS."}]},"generator":{"engine":"Vulnogram 0.0.9"},"impact":{"cvss":{"attackComplexity":"HIGH","attackVector":"LOCAL","availabilityImpact":"HIGH","baseScore":4.7,"baseSeverity":"MEDIUM","confidentialityImpact":"NONE","integrityImpact":"NONE","privilegesRequired":"LOW","scope":"UNCHANGED","userInteraction":"NONE","vectorString":"CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:N/I:N/A:H","version":"3.1"}},"problemtype":{"problemtype_data":[{"description":[{"lang":"eng","value":"CWE-642 External Control of Critical State Data"}]}]},"references":{"reference_data":[{"refsource":"MISC","url":"https://security.paloaltonetworks.com/CVE-2020-1976","name":"https://security.paloaltonetworks.com/CVE-2020-1976"}]},"solution":[{"lang":"eng","value":"This issue is fixed in GlobalProtect 5.0.6, GlobalProtect 5.1.0, and all later versions.\n"}],"source":{"defect":["GPC-9616"],"discovery":"INTERNAL"},"work_around":[{"lang":"eng","value":"n/a"}]},"nvd":{"publishedDate":"2020-02-12 23:15:00","lastModifiedDate":"2020-05-04 14:14:00","problem_types":["CWE-20"],"metrics":{"baseMetricV3":{"cvssV3":{"version":"3.1","vectorString":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H","attackVector":"LOCAL","attackComplexity":"LOW","privilegesRequired":"LOW","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"NONE","integrityImpact":"NONE","availabilityImpact":"HIGH","baseScore":5.5,"baseSeverity":"MEDIUM"},"exploitabilityScore":1.8,"impactScore":3.6},"baseMetricV2":{"cvssV2":{"version":"2.0","vectorString":"AV:L/AC:L/Au:N/C:N/I:N/A:C","accessVector":"LOCAL","accessComplexity":"LOW","authentication":"NONE","confidentialityImpact":"NONE","integrityImpact":"NONE","availabilityImpact":"COMPLETE","baseScore":4.9},"severity":"MEDIUM","exploitabilityScore":3.9,"impactScore":6.9,"acInsufInfo":false,"obtainAllPrivilege":false,"obtainUserPrivilege":false,"obtainOtherPrivilege":false,"userInteractionRequired":false}},"configurations":{"CVE_data_version":"4.0","nodes":[{"operator":"OR","children":[],"cpe_match":[{"vulnerable":true,"cpe23Uri":"cpe:2.3:a:paloaltonetworks:globalprotect:*:*:*:*:*:macos:*:*","versionStartIncluding":"5.0","versionEndIncluding":"5.0.5","cpe_name":[]}]}]}},"legacy_mitre":{"record":{"CveYear":"2020","CveId":"1976","Ordinal":"161446","Title":"CVE-2020-1976","CVE":"CVE-2020-1976","Year":"2020"},"notes":[{"CveYear":"2020","CveId":"1976","Ordinal":"1","NoteData":"A denial-of-service (DoS) vulnerability in Palo Alto Networks GlobalProtect software running on Mac OS allows authenticated local users to cause the Mac OS kernel to hang or crash. This issue affects GlobalProtect 5.0.5 and earlier versions of GlobalProtect 5.0 on Mac OS.","Type":"Description","Title":null},{"CveYear":"2020","CveId":"1976","Ordinal":"2","NoteData":"2020-02-12","Type":"Other","Title":"Published"},{"CveYear":"2020","CveId":"1976","Ordinal":"3","NoteData":"2020-02-12","Type":"Other","Title":"Modified"}]}}}