QID 730157
Date Published: 2021-08-18
QID 730157: Palo Alto Networks PAN-OS Improper SAML Authentication Vulnerability in GlobalProtect Portal (PAN-150023)
PAN OS is the software that runs all Palo Alto Networks next-generation firewalls.
An improper authentication vulnerability exists in Palo Alto Networks PAN-OS software that enables a SAML authenticated attacker to impersonate any other user in the GlobalProtect Portal and GlobalProtect Gateway when they are configured to use SAML authentication.
Affected Versions:
PAN-OS 8.1 versions earlier than PAN-OS 8.1.19
PAN-OS 9.0 versions earlier than PAN-OS 9.0.14
PAN-OS 9.1 versions earlier than PAN-OS 9.1.9
PAN-OS 10.0 versions earlier than PAN-OS 10.0.5
QID Detection Logic (Authenticated):
This QID looks for the vulnerable version of PAN-OS via XML API.
NOTE: This vulnerability applies only to PAN-OS firewalls configured to have a GlobalProtect portal or gateway with SAML authentication enabled.
An improper authentication vulnerability exists in Palo Alto Networks PAN-OS software that enables a SAML authenticated attacker to impersonate any other user in the GlobalProtect Portal and GlobalProtect Gateway when they are configured to use SAML authentication.
Refer to PAN-150023 for more information about patching this vulnerability.Workaround:
You can disable SAML authentication for any impacted GlobalProtect portal or gateway until you upgrade the PAN-OS firewall to a fixed version.
- PAN-150023 -
security.paloaltonetworks.com/CVE-2021-3046
CVEs related to QID 730157
| Advisory ID | Software | Component | Link |
|---|---|---|---|
| PAN-150023 |
|