CVE-2024-5918
Published: Nov 14, 2024
Modified: Nov 14, 2024
Description
An improper certificate validation vulnerability in Palo Alto Networks PAN-OS software enables an authorized user with a specially crafted client certificate to connect to an impacted GlobalProtect portal or GlobalProtect gateway as a different legitimate user. This attack is possible only if you "Allow Authentication with User Credentials OR Client Certificate."
| Vendor | Product | Versions |
|---|---|---|
Palo Alto Networks | Cloud NGFW | unaffected All |
Palo Alto Networks | PAN-OS | unaffected 11.2.0unaffected 11.1.0affected 11.0.0 - < 11.0.3affected 10.2.0 - < 10.2.4-h5affected 10.1.0 - < 10.1.11 |
Palo Alto Networks | Prisma Access | unaffected All |
Weaknesses (CWE)
References
Security Training
Train your team to recognize and prevent security threats with our comprehensive security awareness program.
Start TrainingVulnerability Scanning
Discover vulnerabilities in your applications and infrastructure before attackers do.
Scan Now