QID 731371
Date Published: 2024-04-11
QID 731371: Palo Alto Networks (PAN-OS) Improper Group Membership Change Vulnerability (PAN-211764, PAN-218522)
PAN OS is the software that runs all Palo Alto Networks next-generation firewalls.
A vulnerability in how Palo Alto Networks PAN-OS software processes data received from Cloud Identity Engine (CIE) agents enables modification of User-ID groups. This impacts user access to network resources where users may be inappropriately denied or allowed access to resources based on your existing Security Policy rules.
Affected Versions:
PAN-OS 11.0 versions earlier than PAN-OS 11.0.3
PAN-OS 10.2 versions earlier than PAN-OS 10.2.5
PAN-OS 10.1 versions earlier than PAN-OS 10.1.11
QID Detection Logic (Authenticated):
This QID looks for the vulnerable version of PAN-OS
A vulnerability in how Palo Alto Networks PAN-OS software processes data received from Cloud Identity Engine (CIE) agents enables modification of User-ID groups. This impacts user access to network resources where users may be inappropriately denied or allowed access to resources based on your existing Security Policy rules.
Refer to CVE-2024-3383 for more information about patching this vulnerability.
- PAN-211764, PAN-218522 -
security.paloaltonetworks.com/CVE-2024-3383
CVEs related to QID 731371
| Advisory ID | Software | Component | Link |
|---|---|---|---|
| CVE-2024-3383 |
|