QID 730255
Date Published: 2021-11-11
QID 730255: Palo Alto Networks (PAN-OS) GlobalProtect Portal and Gateway Interfaces Memory Corruption Vulnerability (PAN-96528)
PAN OS is the software that runs all Palo Alto Networks next-generation firewalls.
A memory corruption vulnerability exists in Palo Alto Networks GlobalProtect portal and gateway interfaces that enables an unauthenticated network-based attacker to disrupt system processes and potentially execute arbitrary code with root privileges. The attacker must have network access to the GlobalProtect interface to exploit this issue.
Prisma Access customers are not impacted by this issue.
Affected Versions:
PAN-OS 8.1 versions earlier than PAN-OS 8.1.17
QID Detection Logic (Authenticated):
This QID looks for the vulnerable version of PAN-OS via XML API.
NOTE:This issue is applicable only to PAN-OS firewall configurations with a GlobalProtect portal or gateway enabled. You can verify whether you have a GlobalProtect portal or gateway configured by checking for entries in 'Network > GlobalProtect > Portals' and in 'Network > GlobalProtect > Gateways' from the web interface.
A memory corruption vulnerability exists in Palo Alto Networks GlobalProtect portal and gateway interfaces that enables an unauthenticated network-based attacker to disrupt system processes and potentially execute arbitrary code with root privileges. The attacker must have network access to the GlobalProtect interface to exploit this issue.
Refer to PAN-96528 for more information about patching this vulnerability.Workaround:
Enable signatures for Unique Threat IDs 91820 and 91855 on traffic destined for GlobalProtect portal and gateway interfaces to block attacks against CVE-2021-3064.
It is not necessary to enable SSL decryption to detect and block attacks against this issue.
- PAN-96528 -
security.paloaltonetworks.com/CVE-2021-3064
CVEs related to QID 730255
| Advisory ID | Software | Component | Link |
|---|---|---|---|
| PAN-96528 |
|