CVE-2024-0009Improper Verification of Source of a Communication Channel in Palo Alto Networks Pan-os

Severity
6.3MEDIUMNVD
CISA6.5
EPSS
0.1%
top 73.66%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedFeb 14
Latest updateJul 26

Description

An improper verification vulnerability in the GlobalProtect gateway feature of Palo Alto Networks PAN-OS software enables a malicious user with stolen credentials to establish a VPN connection from an unauthorized IP address.

CVSS vector

CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:LExploitability: 2.8 | Impact: 3.4

Affected Packages5 packages

NVDpaloaltonetworks/pan-os10.2.010.2.4+1
CVEListV5palo_alto_networks/pan-os10.210.2.4+1
Palo Altopaloalto/pan-os

🔴Vulnerability Details

3
GHSA
Reflected Cross Site-Scripting (XSS) in Oveleon Cookiebar2024-07-26
CVEList
PAN-OS: Improper IP Address Verification in GlobalProtect Gateway2024-02-14
GHSA
GHSA-9ppw-9f8w-5r25: An improper verification vulnerability in the GlobalProtect gateway feature of Palo Alto Networks PAN-OS software enables a malicious user with stolen2024-02-14

📋Vendor Advisories

2
CISA
VMware vCenter Server Incorrect Default File Permissions Vulnerability2024-07-17
Palo Alto
PAN-OS: Improper IP Address Verification in GlobalProtect Gateway2024-02-14
CVE-2024-0009 — Palo Alto Networks Pan-os vulnerability | cvebase