QID 376116
Date Published: 2021-12-01
QID 376116: Palo Alto Networks (GlobalProtect App) Incorrect Privilege Assignment Allows Local Privilege Escalation Vulnerability (GPC-9358)
An incorrect privilege assignment vulnerability when writing application-specific files in the Palo Alto Networks GlobalProtect App for Linux on ARM platform allows a local authenticated user to gain root privileges on the system.
Affected Versions:
Palo Alto Networks GlobalProtect App for Linux 5.0 versions before 5.0.8
Palo Alto Networks GlobalProtect App for Linux 5.1 versions before 5.1.1
QID Detection Logic (Authenticated):
This QID looks for the vulnerable version of GlobalProtect App for Linux
An incorrect privilege assignment vulnerability when writing application-specific files in the Palo Alto Networks GlobalProtect App for Linux on ARM platform allows a local authenticated user to gain root privileges on the system.
Refer to GPC-9358 for more information about patching this vulnerability.
Workaround:
There are no viable workarounds for this issue.
- GPC-9358 -
security.paloaltonetworks.com/CVE-2020-1989
CVEs related to QID 376116
| Advisory ID | Software | Component | Link |
|---|---|---|---|
| GPC-9358 |
|