Palo Alto Networks GlobalProtect X.509 Certificate Validation Security Bypass Vulnerability
BID:56104
Info
Palo Alto Networks GlobalProtect X.509 Certificate Validation Security Bypass Vulnerability
| Bugtraq ID: | 56104 |
| Class: | Environment Error |
| CVE: |
CVE-2012-6606 |
| Remote: | Yes |
| Local: | No |
| Published: | Oct 12 2012 12:00AM |
| Updated: | Mar 19 2015 08:26AM |
| Credit: | Micha Borrmann |
| Vulnerable: |
Paloaltonetworks GlobalProtect 1.1.6 Paloaltonetworks GlobalProtect 1.1.5 |
| Not Vulnerable: |
Paloaltonetworks GlobalProtect 1.1.7 |
Discussion
Palo Alto Networks GlobalProtect X.509 Certificate Validation Security Bypass Vulnerability
Palo Alto Networks GlobalProtect is prone to a security-bypass vulnerability because the application fails to properly validate X.509 certificates.
Successfully exploiting this issue allows attackers to perform man-in-the-middle attacks and bypass certain security restrictions.
Palo Alto Networks GlobalProtect 1.1.5 is vulnerable; other versions may also be affected.
Palo Alto Networks GlobalProtect is prone to a security-bypass vulnerability because the application fails to properly validate X.509 certificates.
Successfully exploiting this issue allows attackers to perform man-in-the-middle attacks and bypass certain security restrictions.
Palo Alto Networks GlobalProtect 1.1.5 is vulnerable; other versions may also be affected.