CVE-2024-5918Improper Certificate Validation in Palo Alto Networks Pan-os

Severity
5.3MEDIUMNVD
EPSS
0.2%
top 63.85%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedNov 14

Description

An improper certificate validation vulnerability in Palo Alto Networks PAN-OS software enables an authorized user with a specially crafted client certificate to connect to an impacted GlobalProtect portal or GlobalProtect gateway as a different legitimate user. This attack is possible only if you "Allow Authentication with User Credentials OR Client Certificate."

CVSS vector

CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:L/VA:N/SC:L/SI:L/SA:L

Affected Packages5 packages

NVDpaloaltonetworks/pan-os10.1.010.1.11+3
CVEListV5palo_alto_networks/pan-os11.0.011.0.3+2
Palo Altopaloalto/pan-os

🔴Vulnerability Details

2
CVEList
PAN-OS: Improper Certificate Validation Enables Impersonation of a Legitimate GlobalProtect User2024-11-14
GHSA
GHSA-xvx4-v362-295f: An improper certificate validation vulnerability in Palo Alto Networks PAN-OS software enables an authorized user with a specially crafted client cert2024-11-14

📋Vendor Advisories

1
Palo Alto
PAN-OS: Improper Certificate Validation Enables Impersonation of a Legitimate GlobalProtect User
CVE-2024-5918 — Improper Certificate Validation in Palo | cvebase