CVE-2024-0009
PAN-OS: Improper IP Address Verification in GlobalProtect Gateway
Severity
Medium 6.3
CVSS 3.1
Exploited
Not listed
EPSS
0.002
7.6th percentile
Discovered by
Customer
Published by the vendor
Published
Feb 14, 2024
Assigned by palo_alto
Description
An improper verification vulnerability in the GlobalProtect gateway feature of Palo Alto Networks PAN-OS software enables a malicious user with stolen credentials to establish a VPN connection from an unauthorized IP address.
Weakness: CWE-940
Affected products
| Vendor | Product | Category | Matched by |
|---|---|---|---|
| Palo Alto Networks | Cloud NGFW | Firewall / NGFW | cna-assigner |
| Palo Alto Networks | PAN-OS | Firewall / NGFW | cna-assigner |
| Palo Alto Networks | Prisma Access | SASE / SSE / Secure Web | cna-assigner |
Vendor-reported affected versions (3)
- Palo Alto Networks · PAN-OS
- Palo Alto Networks · Prisma Access
- Palo Alto Networks · Cloud NGFW
Credit
Palo Alto Networks thanks Matthew Fong for discovering and reporting this issue.
Vendor remediation
This issue is fixed in PAN-OS 10.2.4, PAN-OS 11.0.1, and all later PAN-OS versions.