CVE-2024-3383

PAN-OS: Improper Group Membership Change Vulnerability in Cloud Identity Engine (CIE)

Severity
High 7.4
CVSS 3.1
Exploited
Not listed
EPSS
0.006
44.2th percentile
Discovered by
Customer
Published by the vendor
Published
Apr 10, 2024
Assigned by palo_alto

Description

A vulnerability in how Palo Alto Networks PAN-OS software processes data received from Cloud Identity Engine (CIE) agents enables modification of User-ID groups. This impacts user access to network resources where users may be inappropriately denied or allowed access to resources based on your existing Security Policy rules.

Weakness: CWE-282

Affected products

Vendor Product Category Matched by
Palo Alto Networks Cloud NGFW Firewall / NGFW cna-assigner
Palo Alto Networks PAN-OS Firewall / NGFW cna-assigner
Palo Alto Networks Prisma Access SASE / SSE / Secure Web cna-assigner
Vendor-reported affected versions (3)
  • Palo Alto Networks · PAN-OS
  • Palo Alto Networks · Cloud NGFW
  • Palo Alto Networks · Prisma Access

Credit

Palo Alto Networks thanks Rodgers Moore, CCIE# 8153 of Insight.com, for discovering and reporting this issue.

Vendor remediation

This issue is fixed in PAN-OS 10.1.11, PAN-OS 10.2.5, PAN-OS 11.0.3, and all later PAN-OS versions.