PT-2024-2989 · Palo Alto Networks · Pan-Os

Ta-Lun Yen

·

Published

2024-04-10

·

Updated

2024-04-10

·

CVE-2024-3388

CVSS v3.1

5.0

Medium

VectorAV:N/AC:L/PR:L/UI:N/S:C/C:N/I:L/A:N
Name of the Vulnerable Software and Affected Versions Palo Alto Networks PAN-OS (affected versions not specified)
Description The issue is related to insecure privilege management in the GlobalProtect Gateway of the PAN-OS software. It allows an authenticated attacker to impersonate another user and send network packets to internal assets, although the attacker cannot receive response packets from those internal assets.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Incorrect Authorization

Improper Privilege Management

Weakness Enumeration

Related Identifiers

BDU:2024-03169
CVE-2024-3388

Affected Products

Pan-Os