CVE-2019-1573
09.04.2019, 22:29
GlobalProtect Agent 4.1.0 for Windows and GlobalProtect Agent 4.1.10 and earlier for macOS may allow a local authenticated attacker who has compromised the end-user account and gained the ability to inspect memory, to access authentication and/or session tokens and replay them to spoof the VPN session and gain access as the user.Enginsight
Vendor | Product | Version |
---|---|---|
paloaltonetworks | globalprotect | 𝑥 ≤ 4.1.0 |
paloaltonetworks | globalprotect | 𝑥 ≤ 4.1.10 |
𝑥
= Vulnerable software versions
Common Weakness Enumeration
- CWE-226 - Sensitive Information in Resource Not Removed Before ReuseThe product releases a resource such as memory or a file so that it can be made available for reuse, but it does not clear or "zeroize" the information contained in the resource before the product performs a critical state transition or makes the resource available for reuse by other entities.
- CWE-311 - Missing Encryption of Sensitive DataThe software does not encrypt sensitive or critical information before storage or transmission.
References