5.3
CVE-2024-5918
- EPSS 0.06%
- Published 14.11.2024 10:15:08
- Last modified 01.10.2025 18:41:27
- Source psirt@paloaltonetworks.com
- Teams watchlist Login
- Open Login
An improper certificate validation vulnerability in Palo Alto Networks PAN-OS software enables an authorized user with a specially crafted client certificate to connect to an impacted GlobalProtect portal or GlobalProtect gateway as a different legitimate user. This attack is possible only if you "Allow Authentication with User Credentials OR Client Certificate."
Verknüpft mit AI von unstrukturierten Daten zu bestehenden CPE der NVD
This information is available to logged-in users. Login
Data is provided by the National Vulnerability Database (NVD)
Paloaltonetworks ≫ Pan-os Version >= 10.1.0 < 10.1.11
Paloaltonetworks ≫ Pan-os Version >= 10.2.0 <= 10.2.4
Paloaltonetworks ≫ Pan-os Version >= 11.0.0 < 11.0.3
Paloaltonetworks ≫ Pan-os Version10.2.4 Update-
Paloaltonetworks ≫ Pan-os Version10.2.4 Updateh2
Paloaltonetworks ≫ Pan-os Version10.2.4 Updateh3
Paloaltonetworks ≫ Pan-os Version10.2.4 Updateh4
Zu dieser CVE wurde keine CISA KEV oder CERT.AT-Warnung gefunden.
Type | Source | Score | Percentile |
---|---|---|---|
EPSS | FIRST.org | 0.06% | 0.177 |
Source | Base Score | Exploit Score | Impact Score | Vector string |
---|---|---|---|---|
nvd@nist.gov | 4.3 | 2.8 | 1.4 |
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N
|
psirt@paloaltonetworks.com | 5.3 | 0 | 0 |
CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:L/VA:N/SC:L/SI:L/SA:L/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:N/R:A/V:C/RE:M/U:Amber
|
CWE-295 Improper Certificate Validation
The product does not validate, or incorrectly validates, a certificate.