QID 375898
Date Published: 2021-09-29
QID 375898: Palo Alto Networks GlobalProtect App Virtual Private Network (VPN) Cookie Local Information Disclosure Vulnerability (GPC-9393)
The GlobalProtect app provides a simple way to extend the enterprise security policies out to mobile endpoints.
Affected Versions :
GlobalProtect App 5.0 versions prior to 5.0.9
GlobalProtect App 5.1 versions prior to 5.1.1
QID Detection Logic (Authenticated):
This checks for vulnerable version of PanGPS.exe file
An information exposure vulnerability in the logging component of Palo Alto Networks GlobalProtect App allows a local authenticated user to read VPN cookie information when the troubleshooting logging level is set to "Dump".
Solution
Refer to Palo Alto security advisory GPC-9393 for updates and patch information.
Vendor References
- GPC-9393 -
security.paloaltonetworks.com/CVE-2020-1987
CVEs related to QID 375898
Software Advisories
| Advisory ID | Software | Component | Link |
|---|---|---|---|
| GPC-9393 |
|