PT-2021-4859 · Palo Alto Networks · Globalprotect
Published
2021-11-10
·
Updated
2022-04-02
·
CVE-2021-3064
CVSS v3.1
10
Critical
| Vector | AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
Palo Alto Networks GlobalProtect portal and gateway interfaces versions prior to PAN-OS 8.1.17
Description
A memory corruption vulnerability exists in the GlobalProtect portal and gateway interfaces, enabling an unauthenticated network-based attacker to disrupt system processes and potentially execute arbitrary code with root privileges. The attacker must have network access to the GlobalProtect interface to exploit this issue.
Recommendations
For versions prior to PAN-OS 8.1.17, update to PAN-OS 8.1.17 or later to resolve the issue. As a temporary workaround, consider restricting access to the GlobalProtect interface to minimize the risk of exploitation.
Fix
Stack Overflow
Memory Corruption
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Globalprotect