PT-2017-14299 · Palo Alto Networks · Globalprotect+1
Craig Stephen
+1
·
Published
2017-12-06
·
Updated
2020-02-17
·
CVE-2017-15942
CVSS v3.1
7.5
High
| Vector | AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H |
Name of the Vulnerable Software and Affected Versions
Palo Alto Networks PAN-OS versions 6.1.18 and earlier
Palo Alto Networks PAN-OS versions 7.0.18 and earlier
Palo Alto Networks PAN-OS versions 7.1.12 and earlier
Palo Alto Networks PAN-OS versions 8.0.5 and earlier
Description
A denial of service issue exists, allowing remote attackers to cause a denial of service via vectors related to the management interface. This vulnerability may lead to denying access to the GlobalProtect portal or GlobalProtect gateway, or prevent configuration commits. The issue is specifically related to the GlobalProtect component and can be exploited by a non-authenticated third party when the GlobalProtect gateway or portal is running.
Recommendations
For versions 6.1.18 and earlier, update to version 6.1.19 or later.
For versions 7.0.18 and earlier, update to version 7.0.19 or later.
For versions 7.1.12 and earlier, update to version 7.1.13 or later.
For versions 8.0.5 and earlier, update to version 8.0.6 or later.
Fix
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Globalprotect
Pan-Os