CVE-2024-0009 — Improper Verification of Source of a Communication Channel in Palo Alto Networks Pan-os
Severity
6.3MEDIUMNVD
CISA6.5
EPSS
0.1%
top 73.66%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedFeb 14
Latest updateJul 26
Description
An improper verification vulnerability in the GlobalProtect gateway feature of Palo Alto Networks PAN-OS software enables a malicious user with stolen credentials to establish a VPN connection from an unauthorized IP address.
CVSS vector
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:LExploitability: 2.8 | Impact: 3.4
Affected Packages5 packages
🔴Vulnerability Details
3GHSA▶
GHSA-9ppw-9f8w-5r25: An improper verification vulnerability in the GlobalProtect gateway feature of Palo Alto Networks PAN-OS software enables a malicious user with stolen↗2024-02-14