Palo Alto Networks Global Protect Agent vulnerabilities

3 known vulnerabilities affecting palo_alto_networks/global_protect_agent.

Total CVEs
3
CISA KEV
0
Public exploits
0
Exploited in wild
0
Severity breakdown
HIGH1MEDIUM1LOW1

Vulnerabilities

Page 1 of 1
CVE-2020-1989HIGHCVSS 7.8≥ 5.0, < 5.0.8≥ 5.1, < 5.1.12020-04-08
CVE-2020-1989 [HIGH] CWE-266 CVE-2020-1989: An incorrect privilege assignment vulnerability when writing application-specific files in the Palo An incorrect privilege assignment vulnerability when writing application-specific files in the Palo Alto Networks Global Protect Agent for Linux on ARM platform allows a local authenticated user to gain root privileges on the system. This issue affects Palo Alto Networks Global Protect Agent for Linux 5.0 versions before 5.0.8; 5.1 versions before 5.1.1.
cvelistv5nvd
CVE-2020-1988MEDIUMCVSS 6.7≥ 5.0, < 5.0.5≥ 4.1, < 4.1.132020-04-08
CVE-2020-1988 [MEDIUM] CWE-428 CVE-2020-1988: An unquoted search path vulnerability in the Windows release of Global Protect Agent allows an authe An unquoted search path vulnerability in the Windows release of Global Protect Agent allows an authenticated local user with file creation privileges on the root of the OS disk (C:\) or to Program Files directory to gain system privileges. This issue affects Palo Alto Networks GlobalProtect Agent 5.0 versions before 5.0.5; 4.1 versions before 4.1.13 o
cvelistv5nvd
CVE-2020-1987LOWCVSS 3.3≥ 5.0, < 5.0.9≥ 5.1, < 5.1.12020-04-08
CVE-2020-1987 [LOW] CWE-200 CVE-2020-1987: An information exposure vulnerability in the logging component of Palo Alto Networks Global Protect An information exposure vulnerability in the logging component of Palo Alto Networks Global Protect Agent allows a local authenticated user to read VPN cookie information when the troubleshooting logging level is set to "Dump". This issue affects Palo Alto Networks Global Protect Agent 5.0 versions prior to 5.0.9; 5.1 versions prior to 5.1.1.
cvelistv5nvd