QID 730273
Date Published: 2021-11-23
QID 730273: Palo Alto Networks (PAN-OS) GlobalProtect Memory Corruption Vulnerability (PAN-149501)
PAN OS is the software that runs all Palo Alto Networks next-generation firewalls.
A memory corruption vulnerability in Palo Alto Networks PAN-OS GlobalProtect Clientless VPN enables an authenticated attacker to execute arbitrary code with root user privileges during SAML authentication.
Affected Version:
PAN-OS 8.1 versions earlier than PAN-OS 8.1.20;
PAN-OS 9.0 versions earlier than PAN-OS 9.0.14;
PAN-OS 9.1 versions earlier than PAN-OS 9.1.9;
PAN-OS 10.0 versions earlier than PAN-OS 10.0.1
QID Detection Logic (Authenticated):
This QID looks for the vulnerable version of PAN-OS
NOTE: This issue is applicable only to PAN-OS firewall configurations with the Clientless VPN feature and SAML authentication enabled for GlobalProtect Portal.
A memory corruption vulnerability in Palo Alto Networks PAN-OS GlobalProtect Clientless VPN enables an authenticated attacker to execute arbitrary code with root user privileges during SAML authentication.
Refer to PAN-149501 for more information about patching this vulnerability.Workaround:
Enable signatures for Unique Threat ID 91585 on traffic processed by the firewall to block attacks against CVE-2021-3056.
- PAN-149501 -
security.paloaltonetworks.com/CVE-2021-3056
CVEs related to QID 730273
| Advisory ID | Software | Component | Link |
|---|---|---|---|
| PAN-149501 |
|