QID 731162
Date Published: 2024-02-21
QID 731162: Palo Alto Networks (PAN-OS) Improper IP Address Verification Vulnerability (PAN-209787)
PAN-OS is the software that runs all Palo Alto Networks next-generation firewalls.
An improper verification vulnerability in the GlobalProtect gateway feature of Palo Alto Networks PAN-OS software enables a malicious user with stolen credentials to establish a VPN connection from an unauthorized IP address.
Affected Versions:
PAN-OS 11.0 versions earlier than PAN-OS 11.0.1
PAN-OS 10.2 versions earlier than PAN-OS 10.2.4
QID Detection Logic (Unauthenticated):
This QID looks for the vulnerable version of PAN-OS.
Note: This QID is marked as potential as this issue is applicable only to PAN-OS firewall configurations with a GlobalProtect gateway enabled. You can verify whether you have a GlobalProtect gateway configured by checking for entries in your firewall web interface (Network > GlobalProtect > Gateways).
Successful exploitation of this vulnerability may compromise the Confidentiality, Integrity, and Availability of data.
- PAN-209787 -
security.paloaltonetworks.com/CVE-2024-0009
CVEs related to QID 731162
| Advisory ID | Software | Component | Link |
|---|---|---|---|
| PAN-209787 |
|