CVE-2020-1989
08.04.2020, 19:15
An incorrect privilege assignment vulnerability when writing application-specific files in the Palo Alto Networks Global Protect Agent for Linux on ARM platform allows a local authenticated user to gain root privileges on the system. This issue affects Palo Alto Networks Global Protect Agent for Linux 5.0 versions before 5.0.8; 5.1 versions before 5.1.1.Enginsight
Vendor | Product | Version |
---|---|---|
paloaltonetworks | globalprotect | 5.0 ≤ 𝑥 < 5.0.8 |
paloaltonetworks | globalprotect | 5.1 ≤ 𝑥 < 5.1.1 |
𝑥
= Vulnerable software versions
Common Weakness Enumeration
- CWE-266 - Incorrect Privilege AssignmentA product incorrectly assigns a privilege to a particular actor, creating an unintended sphere of control for that actor.
- CWE-269 - Improper Privilege ManagementThe software does not properly assign, modify, track, or check privileges for an actor, creating an unintended sphere of control for that actor.