CVE-2024-8691
11.09.2024, 17:15
A vulnerability in the GlobalProtect portal in Palo Alto Networks PAN-OS software enables a malicious authenticated GlobalProtect user to impersonate another GlobalProtect user. Active GlobalProtect users impersonated by an attacker who is exploiting this vulnerability are disconnected from GlobalProtect. Upon exploitation, PAN-OS logs indicate that the impersonated user authenticated to GlobalProtect, which hides the identity of the attacker.Enginsight
Vendor | Product | Version |
---|---|---|
paloaltonetworks | pan-os | 9.1.0 ≤ 𝑥 < 9.1.17 |
paloaltonetworks | pan-os | 10.1.0 ≤ 𝑥 < 10.1.11 |
𝑥
= Vulnerable software versions