QID 375826
Date Published: 2021-09-07
QID 375826: Palo Alto GlobalProtect App Multiple Vulnerabilities
The GlobalProtect app provides a simple way to extend the enterprise security policies out to mobile endpoints.
CVE-2020-2032 GlobalProtect App: File race condition vulnerability leads to local privilege escalation during upgrade.
CVE-2020-2033 GlobalProtect App: Missing certificate validation vulnerability can disclose pre-logon authentication cookie
Affected Versions :
GlobalProtect app 5.0 versions earlier than GlobalProtect app 5.0.10 on Windows;
GlobalProtect app 5.1 versions earlier than GlobalProtect app 5.1.4 on Windows.
QID Detection Logic (Authenticated):
This checks for vulnerable version of PanGPS.exe file
On successful exploitation it allows the attacker to access the GlobalProtect Server as allowed by configured Security rules for the 'pre-login' user.
- CVE-2020-2032 -
security.paloaltonetworks.com/CVE-2020-2032 - CVE-2020-2033 -
security.paloaltonetworks.com/CVE-2020-2033
CVEs related to QID 375826
| Advisory ID | Software | Component | Link |
|---|---|---|---|
| CVE-2020-2032 | Windows |
|
|
| CVE-2020-2033 | Windows |
|