Palo Alto Networks GlobalProtect Vulnerability: Impersonation of Authenticated Users
CVE-2024-8691
7.1HIGH
Key Information:
- Vendor
- Palo Alto Networks
- Vendor
- CVE Published:
- 11 September 2024
Summary
The vulnerability in the GlobalProtect portal of Palo Alto Networks PAN-OS software allows malicious actors, who are already authenticated GlobalProtect users, to impersonate other active users. When this occurs, the impersonated users are forcibly disconnected from the GlobalProtect service, thus compromising session integrity and disrupting connectivity. Furthermore, PAN-OS logs inaccurately indicate that the impersonated user has successfully authenticated, masking the attacker's identity and actions, creating challenges in monitoring and forensic analysis.
Affected Version(s)
PAN-OS 9.1.0 < 9.1.17
PAN-OS 10.1.0 < 10.1.11
Cloud NGFW All
References
CVSS V3.1
Score:
7.1
Severity:
HIGH
Confidentiality:
None
Integrity:
High
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Unchanged
Timeline
Vulnerability published
Vulnerability Reserved
Credit
Claudiu Pancotan