QID 379514
Date Published: 2024-03-21
QID 379514: Palo Alto Networks (PAN-OS) (GlobalProtect App) Privilege Escalation Vulnerability (GPC-15349)
An issue in the Palo Alto Networks GlobalProtect app enables a non-privileged user to disable the GlobalProtect app without needing the passcode in configurations that allow a user to disable GlobalProtect with a passcode.
Affected Versions:
GlobalProtect App 5.1 versions earlier than GlobalProtect App 5.1.12
GlobalProtect App 5.2 versions earlier than GlobalProtect App 5.2.13
GlobalProtect App 6.0 versions earlier than GlobalProtect App 6.0.4
GlobalProtect App 6.1 versions earlier than GlobalProtect App 6.1.1
QID Detection Logic (Authenticated):
This QID looks for the vulnerable version of PAN-OS
NOTE:This issue is applicable only to devices configured to use the GlobalProtect Connect Before Logon feature.
A successfully exploited of the vulnerability could allow an non-privileged user to disable the GlobalProtect app without needing the passcode in configurations that allow a user to disable GlobalProtect with a passcode.
Refer to GPC-15349 for more information about patching this vulnerability.
- GPC-15349 -
security.paloaltonetworks.com/CVE-2024-2431
CVEs related to QID 379514
| Advisory ID | Software | Component | Link |
|---|---|---|---|
| GPC-15349 |
|