QID 730275
Date Published: 2021-11-23
QID 730275: Palo Alto Networks (PAN-OS) GlobalProtect Improper Access Control Vulnerability (PAN-164422)
PAN OS is the software that runs all Palo Alto Networks next-generation firewalls.
An improper access control vulnerability in PAN-OS software enables an attacker with authenticated access to GlobalProtect portals and gateways to connect to the EC2 instance metadata endpoint for VM-Series firewalls hosted on Amazon AWS.
Affected Version:
PAN-OS 8.1 versions earlier than PAN-OS 8.1.20 VM-Series firewalls;
PAN-OS 9.1 versions earlier than PAN-OS 9.1.11 VM-Series firewalls;
PAN-OS 9.0 versions earlier than PAN-OS 9.0.14 VM-Series firewalls;
PAN-OS 10.0 versions earlier than PAN-OS 10.0.8 VM-Series firewalls.
QID Detection Logic (Authenticated):
This QID looks for the vulnerable version of PAN-OS
NOTE: This issue is applicable only to PAN-OS firewall configurations with a GlobalProtect portal or gateway enabled.
An improper access control vulnerability in PAN-OS software enables an attacker with authenticated access to GlobalProtect portals and gateways to connect to the EC2 instance metadata endpoint for VM-Series firewalls hosted on Amazon AWS.
Exploitation of this vulnerability enables an attacker to perform any operations allowed by the EC2 role in AWS.
Refer to PAN-164422 for more information about patching this vulnerability.
- PAN-164422 -
security.paloaltonetworks.com/CVE-2021-3062
CVEs related to QID 730275
| Advisory ID | Software | Component | Link |
|---|---|---|---|
| PAN-164422 |
|