PT-2017-14299 · Palo Alto Networks · Globalprotect+1
Craig Stephen
+1
·
Publicado
2017-12-06
·
Atualizado
2020-02-17
·
CVE-2017-15942
CVSS v3.1
7.5
Alta
| Vetor | AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H |
Name of the Vulnerable Software and Affected Versions
Palo Alto Networks PAN-OS versions 6.1.18 and earlier
Palo Alto Networks PAN-OS versions 7.0.18 and earlier
Palo Alto Networks PAN-OS versions 7.1.12 and earlier
Palo Alto Networks PAN-OS versions 8.0.5 and earlier
Description
A denial of service issue exists, allowing remote attackers to cause a denial of service via vectors related to the management interface. This vulnerability may lead to denying access to the GlobalProtect portal or GlobalProtect gateway, or prevent configuration commits. The issue is specifically related to the GlobalProtect component and can be exploited by a non-authenticated third party when the GlobalProtect gateway or portal is running.
Recommendations
For versions 6.1.18 and earlier, update to version 6.1.19 or later.
For versions 7.0.18 and earlier, update to version 7.0.19 or later.
For versions 7.1.12 and earlier, update to version 7.1.13 or later.
For versions 8.0.5 and earlier, update to version 8.0.6 or later.
Correção
Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾
Identificadores relacionados
Produtos afetados
Globalprotect
Pan-Os