QID 375898

Date Published: 2021-09-29

QID 375898: Palo Alto Networks GlobalProtect App Virtual Private Network (VPN) Cookie Local Information Disclosure Vulnerability (GPC-9393)

The GlobalProtect app provides a simple way to extend the enterprise security policies out to mobile endpoints.

Affected Versions :
GlobalProtect App 5.0 versions prior to 5.0.9
GlobalProtect App 5.1 versions prior to 5.1.1

QID Detection Logic (Authenticated):
This checks for vulnerable version of PanGPS.exe file

An information exposure vulnerability in the logging component of Palo Alto Networks GlobalProtect App allows a local authenticated user to read VPN cookie information when the troubleshooting logging level is set to "Dump".

  • CVSS V3 rated as Medium - 3.3 severity.
  • CVSS V2 rated as Low - 2.1 severity.
  • Solution
    Refer to Palo Alto security advisory GPC-9393 for updates and patch information.
    Vendor References

    CVEs related to QID 375898

    Software Advisories
    Advisory ID Software Component Link
    GPC-9393 URL Logo security.paloaltonetworks.com/CVE-2020-1987