CVE-2024-2431Improper Privilege Management in Palo Alto Networks Globalprotect APP

Severity
5.5MEDIUMNVD
EPSS
0.0%
top 85.52%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedMar 13

Description

An issue in the Palo Alto Networks GlobalProtect app enables a non-privileged user to disable the GlobalProtect app in configurations that allow a user to disable GlobalProtect with a passcode.

CVSS vector

CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:HExploitability: 1.8 | Impact: 3.6

Affected Packages3 packages

NVDpaloaltonetworks/globalprotect5.1.05.1.12+3
CVEListV5palo_alto_networks/globalprotect_app6.06.0.4+3

🔴Vulnerability Details

2
GHSA
GHSA-vr6p-mmxj-phm2: An issue in the Palo Alto Networks GlobalProtect app enables a non-privileged user to disable the GlobalProtect app in configurations that allow a use2024-03-13
CVEList
GlobalProtect App: Local User Can Disable GlobalProtect2024-03-13

📋Vendor Advisories

1
Palo Alto
GlobalProtect App: Local User Can Disable GlobalProtect2024-03-13
CVE-2024-2431 — Improper Privilege Management in Palo | cvebase