CVE-2024-8691
Published: Sep 11, 2024
Modified: Sep 11, 2024
Description
A vulnerability in the GlobalProtect portal in Palo Alto Networks PAN-OS software enables a malicious authenticated GlobalProtect user to impersonate another GlobalProtect user. Active GlobalProtect users impersonated by an attacker who is exploiting this vulnerability are disconnected from GlobalProtect. Upon exploitation, PAN-OS logs indicate that the impersonated user authenticated to GlobalProtect, which hides the identity of the attacker.
| Vendor | Product | Versions |
|---|---|---|
Palo Alto Networks | PAN-OS | affected 9.1.0 - < 9.1.17affected 10.1.0 - < 10.1.11unaffected 10.2.0unaffected 11.0.0unaffected 11.1.0+1 more versions |
Palo Alto Networks | Cloud NGFW | unaffected All |
Palo Alto Networks | Prisma Access | unaffected All |
Weaknesses (CWE)
Security Training
Train your team to recognize and prevent security threats with our comprehensive security awareness program.
Start TrainingVulnerability Scanning
Discover vulnerabilities in your applications and infrastructure before attackers do.
Scan Now