CVE-2024-5918
14.11.2024, 10:15
An improper certificate validation vulnerability in Palo Alto Networks PAN-OS software enables an authorized user with a specially crafted client certificate to connect to an impacted GlobalProtect portal or GlobalProtect gateway as a different legitimate user. This attack is possible only if you "Allow Authentication with User Credentials OR Client Certificate."Enginsight
Vendor | Product | Version |
---|---|---|
paloaltonetworks | pan-os | 10.1.0 ≤ 𝑥 < 10.1.11 |
paloaltonetworks | pan-os | 10.2.0 ≤ 𝑥 ≤ 10.2.4 |
paloaltonetworks | pan-os | 11.0.0 ≤ 𝑥 < 11.0.3 |
paloaltonetworks | pan-os | 10.2.4 |
paloaltonetworks | pan-os | 10.2.4:h2 |
paloaltonetworks | pan-os | 10.2.4:h3 |
paloaltonetworks | pan-os | 10.2.4:h4 |
𝑥
= Vulnerable software versions
Common Weakness Enumeration