PT-2021-4859 · Palo Alto Networks · Globalprotect

Published

2021-11-10

·

Updated

2022-04-02

·

CVE-2021-3064

CVSS v3.1

10

Critical

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Palo Alto Networks GlobalProtect portal and gateway interfaces versions prior to PAN-OS 8.1.17
Description A memory corruption vulnerability exists in the GlobalProtect portal and gateway interfaces, enabling an unauthenticated network-based attacker to disrupt system processes and potentially execute arbitrary code with root privileges. The attacker must have network access to the GlobalProtect interface to exploit this issue.
Recommendations For versions prior to PAN-OS 8.1.17, update to PAN-OS 8.1.17 or later to resolve the issue. As a temporary workaround, consider restricting access to the GlobalProtect interface to minimize the risk of exploitation.

Fix

Stack Overflow

Memory Corruption

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

BDU:2021-05587
CVE-2021-3064

Affected Products

Globalprotect