PT-2024-10388 · Palo Alto Networks · Palo Alto Networks Globalprotect

David Cash

+3

·

Published

2024-06-12

·

Updated

2025-08-26

·

CVE-2024-5921

CVSS v3.1

8.8

High

VectorAV:A/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Palo Alto Networks GlobalProtect (affected versions not specified)
Description The issue is related to an insufficient certification validation in the GlobalProtect app, allowing attackers to connect the app to arbitrary servers. This can enable a local non-administrative operating system user or an attacker on the same subnet to install malicious root certificates on the endpoint and subsequently install malicious software signed by the malicious root certificates on that endpoint. Over 1.4 million results are found to be potentially affected. The vulnerability can be exploited to achieve remote code execution and privilege escalation.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability. However, it is recommended to update to version 6.2.6 and make the required registry changes, including setting "cert-store" to "machine", "cert-location" to "ROOT", and "full-chain-cert-verify" to "yes". Additionally, ensure the full cert chain is installed in the root cert directory. If issues persist, consider temporarily disabling the vulnerable component or restricting access to the affected API endpoints until a patch is available. Note that using an ECC cert with GP 6.2.6 in FIPS-CC mode may result in "Non compliant FIPS-CC mode certificate" errors. As a workaround, using a GoDaddy or ssl dot com cert may resolve OCSP/CRL issues.

Exploit

Improper Authentication

Improper Certificate Validation

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

BDU:2025-00897
CVE-2024-5921

Affected Products

Palo Alto Networks Globalprotect