PT-2024-39178 · Palo Alto Networks · Pan-Os

Claudiu Pancotan

·

Published

2024-09-11

·

Updated

2024-11-01

·

CVE-2024-8691

CVSS v3.1

7.1

High

VectorAV:N/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:L
Name of the Vulnerable Software and Affected Versions: Palo Alto Networks PAN-OS software (affected versions not specified)
Description: A vulnerability in the GlobalProtect portal enables a malicious authenticated GlobalProtect user to impersonate another GlobalProtect user. Active GlobalProtect users impersonated by an attacker are disconnected from GlobalProtect. Upon exploitation, PAN-OS logs indicate that the impersonated user authenticated to GlobalProtect, which hides the identity of the attacker.
Recommendations: At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Incorrect Authorization

Weakness Enumeration

Related Identifiers

BDU:2025-02027
CVE-2024-8691

Affected Products

Pan-Os