CVE-2020-1987Sensitive Information Exposure in Palo Alto Networks Global Protect Agent

Severity
3.3LOWNVD
CNA3.9
EPSS
0.0%
top 86.14%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedApr 8
Latest updateMay 24

Description

An information exposure vulnerability in the logging component of Palo Alto Networks Global Protect Agent allows a local authenticated user to read VPN cookie information when the troubleshooting logging level is set to "Dump". This issue affects Palo Alto Networks Global Protect Agent 5.0 versions prior to 5.0.9; 5.1 versions prior to 5.1.1.

CVSS vector

CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:NExploitability: 1.8 | Impact: 1.4

Affected Packages3 packages

🔴Vulnerability Details

2
GHSA
GHSA-x3ph-r68g-gghq: An information exposure vulnerability in the logging component of Palo Alto Networks Global Protect Agent allows a local authenticated user to read VP2022-05-24
CVEList
Global Protect Agent: VPN cookie local information disclosure2020-04-08

📋Vendor Advisories

1
Palo Alto
GlobalProtect App: VPN cookie local information disclosure2020-04-08

💬Community

8
Bugzilla
CVE-2020-11764 OpenEXR: out-of-bounds write in copyIntoFrameBuffer function in ImfMisc.cpp2020-04-28
Bugzilla
CVE-2020-11765 OpenEXR: off-by-one error in ImfXdr.h read function by DwaCompressor::Classifier::Classifier leading to an out-of-bounds read2020-04-28
Bugzilla
CVE-2020-11760 OpenEXR: out-of-bounds read during RLE uncompression in rleUncompress function in ImfRle.cpp2020-04-28
Bugzilla
CVE-2020-11761 OpenEXR: out-of-bounds read during Huffman uncompression2020-04-28
Bugzilla
CVE-2020-11763 OpenEXR: std::vector out-of-bounds read and write in ImfTileOffsets.cpp2020-04-28
CVE-2020-1987 — Sensitive Information Exposure in Palo | cvebase