5.2
CVE-2026-0297
- EPSS 0.16%
- Veröffentlicht 13.08.2026 02:01:13
- Zuletzt bearbeitet 18.08.2026 15:04:46
- CVE-Watchlists
- Unerledigt
GlobalProtect App: Buffer Overflow Vulnerability during UDP Tunnel Handshake
A buffer overflow vulnerability exists in the Palo Alto Networks GlobalProtect™ app that enables a man-in-the-middle (MitM) attacker or a rogue gateway to disrupt system processes and potentially execute arbitrary code with elevated privileges (SYSTEM privileges on Windows, and root privileges on macOS and Linux).
Daten sind bereitgestellt durch das CVE Programm von einer CVE Numbering Authority (CNA) (Unstrukturiert).
HerstellerPalo Alto Networks
≫
Produkt
GlobalProtect App
Default Statusunaffected
Version
6.3.0
Version <
6.3.3-h15
Status
affected
Version
6.2.0
Status
affected
Version
6.0.0
Version <
6.0.15
Status
affected
HerstellerPalo Alto Networks
≫
Produkt
GlobalProtect App
Default Statusunaffected
Version
6.3.0
Version <
6.3.3-h14
Status
affected
Version
6.2.0
Version <
6.2.8-h13
Status
affected
Version
6.0.0
Version <
6.0.15
Status
affected
HerstellerPalo Alto Networks
≫
Produkt
GlobalProtect App
Default Statusunaffected
Version
6.3.0
Version <
6.3.5
Status
affected
Version
6.0.0
Version <
6.0.15
Status
affected
VulnDex Vulnerability Enrichment
| Typ | Quelle | Score | Percentile |
|---|---|---|---|
| EPSS | FIRST.org | 0.16% | 0.06 |
| Quelle | Base Score | Exploit Score | Impact Score | Vector String |
|---|---|---|---|---|
| psirt@paloaltonetworks.com | 5.2 | 0 | 0 |
CVSS:4.0/AV:A/AC:L/AT:P/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:U/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:N/R:U/V:D/RE:M/U:Amber
|
CWE-787 Out-of-bounds Write
The product writes data past the end, or before the beginning, of the intended buffer.
https://security.paloaltonetworks.com/CVE-2026-0297