CVE Database
/

CVE-2024-8691

Back to search

CVE-2024-8691

Published: Sep 11, 2024

Modified: Sep 11, 2024

PUBLISHED

Description

A vulnerability in the GlobalProtect portal in Palo Alto Networks PAN-OS software enables a malicious authenticated GlobalProtect user to impersonate another GlobalProtect user. Active GlobalProtect users impersonated by an attacker who is exploiting this vulnerability are disconnected from GlobalProtect. Upon exploitation, PAN-OS logs indicate that the impersonated user authenticated to GlobalProtect, which hides the identity of the attacker.

VendorProductVersions

Palo Alto Networks

PAN-OS

affected
9.1.0 - < 9.1.17
affected
10.1.0 - < 10.1.11
unaffected
10.2.0
unaffected
11.0.0
unaffected
11.1.0

+1 more versions

Palo Alto Networks

Cloud NGFW

unaffected
All

Palo Alto Networks

Prisma Access

unaffected
All

Weaknesses (CWE)

Security Training

Train your team to recognize and prevent security threats with our comprehensive security awareness program.

Start Training

Vulnerability Scanning

Discover vulnerabilities in your applications and infrastructure before attackers do.

Scan Now