4.3

CVE-2024-5918

PAN-OS: Improper Certificate Validation Enables Impersonation of a Legitimate GlobalProtect User

An improper certificate validation vulnerability in Palo Alto Networks PAN-OS software enables an authorized user with a specially crafted client certificate to connect to an impacted GlobalProtect portal or GlobalProtect gateway as a different legitimate user. This attack is possible only if you "Allow Authentication with User Credentials OR Client Certificate."
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Paloaltonetworks ≫ Pan-os Version >= 10.1.0 < 10.1.11
Paloaltonetworks ≫ Pan-os Version >= 10.2.0 <= 10.2.4
Paloaltonetworks ≫ Pan-os Version >= 11.0.0 < 11.0.3
Paloaltonetworks ≫ Pan-os Version 10.2.4 Update -
Paloaltonetworks ≫ Pan-os Version 10.2.4 Update h2
Paloaltonetworks ≫ Pan-os Version 10.2.4 Update h3
Paloaltonetworks ≫ Pan-os Version 10.2.4 Update h4
VulnDex Vulnerability Enrichment
Diese Information steht angemeldeten Benutzern zur Verfügung. Login Login
Zu dieser CVE wurde keine Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 0.17% 0.067
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
NIST 4.3 2.8 1.4
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N
psirt@paloaltonetworks.com 5.3 0 0
CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:L/VA:N/SC:L/SI:L/SA:L/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:N/R:A/V:C/RE:M/U:Amber
CWE-295 Improper Certificate Validation

The product does not validate, or incorrectly validates, a certificate.

https://security.paloaltonetworks.com/CVE-2024-5918
Vendor Advisory