Search

Find a vulnerability

Search criteria

    5 vulnerabilities found for globalprotect by paloaltonetworks

    CVE-2024-9473 (GCVE-0-2024-9473)

    Vulnerability from cvelistv5 โ€“ Published: 2024-10-09 17:07 โ€“ Updated: 2024-10-18 11:59
    VLAI
    Title
    GlobalProtect App: Local Privilege Escalation (PE) Vulnerability
    Summary
    A privilege escalation vulnerability in the Palo Alto Networks GlobalProtect app on Windows allows a locally authenticated non-administrative Windows user to escalate their privileges to NT AUTHORITY/SYSTEM through the use of the repair functionality offered by the .msi file used to install GlobalProtect.
    SSVC
    Exploitation: poc Automatable: no Technical Impact: total
    CISA Coordinator ยท CISA-ADP (v2.0.3)
    Decision recorded 2024-10-15 12:53 UTC
    CWE
    • CWE-250 - Execution with Unnecessary Privileges
    Impacted products
    Vendor Product Version
    Palo Alto Networks GlobalProtect App Affected: 5.1
    Affected: 6.0
    Affected: 6.1
    Affected: 6.2.0 , < 6.2.5 (custom)
    Affected: 6.3
        cpe:2.3:a:paloaltonetworks:globalprotect_app:6.3.1:-:*:*:*:*:*:*
        cpe:2.3:a:paloaltonetworks:globalprotect_app:6.3.0:-:*:*:*:*:*:*
        cpe:2.3:a:paloaltonetworks:globalprotect_app:6.2.4:-:*:*:*:*:*:*
        cpe:2.3:a:paloaltonetworks:globalprotect_app:6.2.3:-:*:*:*:*:*:*
        cpe:2.3:a:paloaltonetworks:globalprotect_app:6.2.2:-:*:*:*:*:*:*
        cpe:2.3:a:paloaltonetworks:globalprotect_app:6.2.1:-:*:*:*:*:*:*
        cpe:2.3:a:paloaltonetworks:globalprotect_app:6.2.0:-:*:*:*:*:*:*
        cpe:2.3:a:paloaltonetworks:globalprotect_app:6.2:-:*:*:*:*:*:*
        cpe:2.3:a:paloaltonetworks:globalprotect_app:6.1.5:-:*:*:*:*:*:*
        cpe:2.3:a:paloaltonetworks:globalprotect_app:6.1.4:-:*:*:*:*:*:*
        cpe:2.3:a:paloaltonetworks:globalprotect_app:6.1.3:-:*:*:*:*:*:*
        cpe:2.3:a:paloaltonetworks:globalprotect_app:6.1.2:-:*:*:*:*:*:*
        cpe:2.3:a:paloaltonetworks:globalprotect_app:6.1.1:-:*:*:*:*:*:*
        cpe:2.3:a:paloaltonetworks:globalprotect_app:6.1.0:-:*:*:*:*:*:*
        cpe:2.3:a:paloaltonetworks:globalprotect_app:6.1:-:*:*:*:*:*:*
        cpe:2.3:a:paloaltonetworks:globalprotect_app:6.0.10:-:*:*:*:*:*:*
        cpe:2.3:a:paloaltonetworks:globalprotect_app:6.0.8:-:*:*:*:*:*:*
        cpe:2.3:a:paloaltonetworks:globalprotect_app:6.0.7:-:*:*:*:*:*:*
        cpe:2.3:a:paloaltonetworks:globalprotect_app:6.0.6:-:*:*:*:*:*:*
        cpe:2.3:a:paloaltonetworks:globalprotect_app:6.0.5:-:*:*:*:*:*:*
        cpe:2.3:a:paloaltonetworks:globalprotect_app:6.0.4:-:*:*:*:*:*:*
        cpe:2.3:a:paloaltonetworks:globalprotect_app:6.0.3:-:*:*:*:*:*:*
        cpe:2.3:a:paloaltonetworks:globalprotect_app:6.0.2:-:*:*:*:*:*:*
        cpe:2.3:a:paloaltonetworks:globalprotect_app:6.0.1:-:*:*:*:*:*:*
        cpe:2.3:a:paloaltonetworks:globalprotect_app:6.0.0:-:*:*:*:*:*:*
        cpe:2.3:a:paloaltonetworks:globalprotect_app:6.0:-:*:*:*:*:*:*
        cpe:2.3:a:paloaltonetworks:globalprotect_app:5.1.12:-:*:*:*:*:*:*
        cpe:2.3:a:paloaltonetworks:globalprotect_app:5.1.11:-:*:*:*:*:*:*
        cpe:2.3:a:paloaltonetworks:globalprotect_app:5.1.10:-:*:*:*:*:*:*
        cpe:2.3:a:paloaltonetworks:globalprotect_app:5.1.9:-:*:*:*:*:*:*
        cpe:2.3:a:paloaltonetworks:globalprotect_app:5.1.8:-:*:*:*:*:*:*
        cpe:2.3:a:paloaltonetworks:globalprotect_app:5.1.7:-:*:*:*:*:*:*
        cpe:2.3:a:paloaltonetworks:globalprotect_app:5.1.6:-:*:*:*:*:*:*
        cpe:2.3:a:paloaltonetworks:globalprotect_app:5.1.5:-:*:*:*:*:*:*
        cpe:2.3:a:paloaltonetworks:globalprotect_app:5.1.4:-:*:*:*:*:*:*
        cpe:2.3:a:paloaltonetworks:globalprotect_app:5.1.3:-:*:*:*:*:*:*
        cpe:2.3:a:paloaltonetworks:globalprotect_app:5.1.2:-:*:*:*:*:*:*
        cpe:2.3:a:paloaltonetworks:globalprotect_app:5.1.1:-:*:*:*:*:*:*
        cpe:2.3:a:paloaltonetworks:globalprotect_app:5.1.0:-:*:*:*:*:*:*
        cpe:2.3:a:paloaltonetworks:globalprotect_app:5.1:-:*:*:*:*:*:*
    Create a notification for this product.
    paloaltonetworks globalprotect Affected: 5.1.0
        cpe:2.3:a:paloaltonetworks:globalprotect:5.1.0:*:*:*:*:windows:*:*
    Create a notification for this product.
    paloaltonetworks globalprotect Affected: 6.0.0
        cpe:2.3:a:paloaltonetworks:globalprotect:6.0.0:*:*:*:*:windows:*:*
    Create a notification for this product.
    paloaltonetworks globalprotect Affected: 6.1.0
        cpe:2.3:a:paloaltonetworks:globalprotect:6.1.0:*:*:*:*:windows:*:*
    Create a notification for this product.
    paloaltonetworks globalprotect Affected: 6.3.0
        cpe:2.3:a:paloaltonetworks:globalprotect:6.3.0:*:*:*:*:windows:*:*
    Create a notification for this product.
    paloaltonetworks globalprotect Affected: 6.2.0 , < 6.2.5 (custom)
        cpe:2.3:a:paloaltonetworks:globalprotect:*:*:*:*:*:windows:*:*
    Create a notification for this product.
    Date Public
    2024-10-09 16:00
    Show details on NVD website

    {
      "containers": {
        "adp": [
          {
            "affected": [
              {
                "cpes": [
                  "cpe:2.3:a:paloaltonetworks:globalprotect:5.1.0:*:*:*:*:windows:*:*"
                ],
                "defaultStatus": "unaffected",
                "product": "globalprotect",
                "vendor": "paloaltonetworks",
                "versions": [
                  {
                    "status": "affected",
                    "version": "5.1.0"
                  }
                ]
              },
              {
                "cpes": [
                  "cpe:2.3:a:paloaltonetworks:globalprotect:6.0.0:*:*:*:*:windows:*:*"
                ],
                "defaultStatus": "unaffected",
                "product": "globalprotect",
                "vendor": "paloaltonetworks",
                "versions": [
                  {
                    "status": "affected",
                    "version": "6.0.0"
                  }
                ]
              },
              {
                "cpes": [
                  "cpe:2.3:a:paloaltonetworks:globalprotect:6.1.0:*:*:*:*:windows:*:*"
                ],
                "defaultStatus": "unaffected",
                "product": "globalprotect",
                "vendor": "paloaltonetworks",
                "versions": [
                  {
                    "status": "affected",
                    "version": "6.1.0"
                  }
                ]
              },
              {
                "cpes": [
                  "cpe:2.3:a:paloaltonetworks:globalprotect:6.3.0:*:*:*:*:windows:*:*"
                ],
                "defaultStatus": "unaffected",
                "product": "globalprotect",
                "vendor": "paloaltonetworks",
                "versions": [
                  {
                    "status": "affected",
                    "version": "6.3.0"
                  }
                ]
              },
              {
                "cpes": [
                  "cpe:2.3:a:paloaltonetworks:globalprotect:*:*:*:*:*:windows:*:*"
                ],
                "defaultStatus": "unaffected",
                "product": "globalprotect",
                "vendor": "paloaltonetworks",
                "versions": [
                  {
                    "lessThan": "6.2.5",
                    "status": "affected",
                    "version": "6.2.0",
                    "versionType": "custom"
                  }
                ]
              }
            ],
            "metrics": [
              {
                "other": {
                  "content": {
                    "id": "CVE-2024-9473",
                    "options": [
                      {
                        "Exploitation": "poc"
                      },
                      {
                        "Automatable": "no"
                      },
                      {
                        "Technical Impact": "total"
                      }
                    ],
                    "role": "CISA Coordinator",
                    "timestamp": "2024-10-15T12:53:19.159087Z",
                    "version": "2.0.3"
                  },
                  "type": "ssvc"
                }
              }
            ],
            "providerMetadata": {
              "dateUpdated": "2024-10-15T13:00:52.468Z",
              "orgId": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
              "shortName": "CISA-ADP"
            },
            "title": "CISA ADP Vulnrichment"
          },
          {
            "providerMetadata": {
              "dateUpdated": "2024-10-10T06:03:45.155Z",
              "orgId": "af854a3a-2127-422b-91ae-364da2661108",
              "shortName": "CVE"
            },
            "references": [
              {
                "url": "http://seclists.org/fulldisclosure/2024/Oct/2"
              }
            ],
            "title": "CVE Program Container"
          }
        ],
        "cna": {
          "affected": [
            {
              "cpes": [
                "cpe:2.3:a:paloaltonetworks:globalprotect_app:6.3.1:-:*:*:*:*:*:*",
                "cpe:2.3:a:paloaltonetworks:globalprotect_app:6.3.0:-:*:*:*:*:*:*",
                "cpe:2.3:a:paloaltonetworks:globalprotect_app:6.2.4:-:*:*:*:*:*:*",
                "cpe:2.3:a:paloaltonetworks:globalprotect_app:6.2.3:-:*:*:*:*:*:*",
                "cpe:2.3:a:paloaltonetworks:globalprotect_app:6.2.2:-:*:*:*:*:*:*",
                "cpe:2.3:a:paloaltonetworks:globalprotect_app:6.2.1:-:*:*:*:*:*:*",
                "cpe:2.3:a:paloaltonetworks:globalprotect_app:6.2.0:-:*:*:*:*:*:*",
                "cpe:2.3:a:paloaltonetworks:globalprotect_app:6.2:-:*:*:*:*:*:*",
                "cpe:2.3:a:paloaltonetworks:globalprotect_app:6.1.5:-:*:*:*:*:*:*",
                "cpe:2.3:a:paloaltonetworks:globalprotect_app:6.1.4:-:*:*:*:*:*:*",
                "cpe:2.3:a:paloaltonetworks:globalprotect_app:6.1.3:-:*:*:*:*:*:*",
                "cpe:2.3:a:paloaltonetworks:globalprotect_app:6.1.2:-:*:*:*:*:*:*",
                "cpe:2.3:a:paloaltonetworks:globalprotect_app:6.1.1:-:*:*:*:*:*:*",
                "cpe:2.3:a:paloaltonetworks:globalprotect_app:6.1.0:-:*:*:*:*:*:*",
                "cpe:2.3:a:paloaltonetworks:globalprotect_app:6.1:-:*:*:*:*:*:*",
                "cpe:2.3:a:paloaltonetworks:globalprotect_app:6.0.10:-:*:*:*:*:*:*",
                "cpe:2.3:a:paloaltonetworks:globalprotect_app:6.0.8:-:*:*:*:*:*:*",
                "cpe:2.3:a:paloaltonetworks:globalprotect_app:6.0.7:-:*:*:*:*:*:*",
                "cpe:2.3:a:paloaltonetworks:globalprotect_app:6.0.6:-:*:*:*:*:*:*",
                "cpe:2.3:a:paloaltonetworks:globalprotect_app:6.0.5:-:*:*:*:*:*:*",
                "cpe:2.3:a:paloaltonetworks:globalprotect_app:6.0.4:-:*:*:*:*:*:*",
                "cpe:2.3:a:paloaltonetworks:globalprotect_app:6.0.3:-:*:*:*:*:*:*",
                "cpe:2.3:a:paloaltonetworks:globalprotect_app:6.0.2:-:*:*:*:*:*:*",
                "cpe:2.3:a:paloaltonetworks:globalprotect_app:6.0.1:-:*:*:*:*:*:*",
                "cpe:2.3:a:paloaltonetworks:globalprotect_app:6.0.0:-:*:*:*:*:*:*",
                "cpe:2.3:a:paloaltonetworks:globalprotect_app:6.0:-:*:*:*:*:*:*",
                "cpe:2.3:a:paloaltonetworks:globalprotect_app:5.1.12:-:*:*:*:*:*:*",
                "cpe:2.3:a:paloaltonetworks:globalprotect_app:5.1.11:-:*:*:*:*:*:*",
                "cpe:2.3:a:paloaltonetworks:globalprotect_app:5.1.10:-:*:*:*:*:*:*",
                "cpe:2.3:a:paloaltonetworks:globalprotect_app:5.1.9:-:*:*:*:*:*:*",
                "cpe:2.3:a:paloaltonetworks:globalprotect_app:5.1.8:-:*:*:*:*:*:*",
                "cpe:2.3:a:paloaltonetworks:globalprotect_app:5.1.7:-:*:*:*:*:*:*",
                "cpe:2.3:a:paloaltonetworks:globalprotect_app:5.1.6:-:*:*:*:*:*:*",
                "cpe:2.3:a:paloaltonetworks:globalprotect_app:5.1.5:-:*:*:*:*:*:*",
                "cpe:2.3:a:paloaltonetworks:globalprotect_app:5.1.4:-:*:*:*:*:*:*",
                "cpe:2.3:a:paloaltonetworks:globalprotect_app:5.1.3:-:*:*:*:*:*:*",
                "cpe:2.3:a:paloaltonetworks:globalprotect_app:5.1.2:-:*:*:*:*:*:*",
                "cpe:2.3:a:paloaltonetworks:globalprotect_app:5.1.1:-:*:*:*:*:*:*",
                "cpe:2.3:a:paloaltonetworks:globalprotect_app:5.1.0:-:*:*:*:*:*:*",
                "cpe:2.3:a:paloaltonetworks:globalprotect_app:5.1:-:*:*:*:*:*:*"
              ],
              "defaultStatus": "unaffected",
              "platforms": [
                "Windows"
              ],
              "product": "GlobalProtect App",
              "vendor": "Palo Alto Networks",
              "versions": [
                {
                  "status": "affected",
                  "version": "5.1"
                },
                {
                  "status": "affected",
                  "version": "6.0"
                },
                {
                  "status": "affected",
                  "version": "6.1"
                },
                {
                  "changes": [
                    {
                      "at": "6.2.5",
                      "status": "unaffected"
                    }
                  ],
                  "lessThan": "6.2.5",
                  "status": "affected",
                  "version": "6.2.0",
                  "versionType": "custom"
                },
                {
                  "status": "affected",
                  "version": "6.3"
                }
              ]
            }
          ],
          "credits": [
            {
              "lang": "en",
              "type": "finder",
              "value": "Michael Baer of SEC Consult Vulnerability Lab"
            },
            {
              "lang": "en",
              "type": "finder",
              "value": "Marc Barrantes of KPMG Spain"
            }
          ],
          "datePublic": "2024-10-09T16:00:00.000Z",
          "descriptions": [
            {
              "lang": "en",
              "supportingMedia": [
                {
                  "base64": false,
                  "type": "text/html",
                  "value": "A privilege escalation vulnerability in the Palo Alto Networks GlobalProtect app on Windows allows a locally authenticated non-administrative Windows user to escalate their privileges to NT AUTHORITY/SYSTEM through the use of the repair functionality offered by the .msi file used to install GlobalProtect."
                }
              ],
              "value": "A privilege escalation vulnerability in the Palo Alto Networks GlobalProtect app on Windows allows a locally authenticated non-administrative Windows user to escalate their privileges to NT AUTHORITY/SYSTEM through the use of the repair functionality offered by the .msi file used to install GlobalProtect."
            }
          ],
          "exploits": [
            {
              "lang": "en",
              "supportingMedia": [
                {
                  "base64": false,
                  "type": "text/html",
                  "value": "Palo Alto Networks is not aware of any malicious exploitation of this issue. However, a proof of concept for this issue is publicly available.\u003cbr\u003e"
                }
              ],
              "value": "Palo Alto Networks is not aware of any malicious exploitation of this issue. However, a proof of concept for this issue is publicly available."
            }
          ],
          "impacts": [
            {
              "capecId": "CAPEC-233",
              "descriptions": [
                {
                  "lang": "en",
                  "value": "CAPEC-233 Privilege Escalation"
                }
              ]
            }
          ],
          "metrics": [
            {
              "cvssV4_0": {
                "Automatable": "NO",
                "Recovery": "USER",
                "Safety": "NOT_DEFINED",
                "attackComplexity": "LOW",
                "attackRequirements": "PRESENT",
                "attackVector": "LOCAL",
                "baseScore": 5.2,
                "baseSeverity": "MEDIUM",
                "privilegesRequired": "LOW",
                "providerUrgency": "AMBER",
                "subAvailabilityImpact": "HIGH",
                "subConfidentialityImpact": "HIGH",
                "subIntegrityImpact": "HIGH",
                "userInteraction": "NONE",
                "valueDensity": "CONCENTRATED",
                "vectorString": "CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:N/VI:L/VA:N/SC:H/SI:H/SA:H/AU:N/R:U/V:C/RE:M/U:Amber",
                "version": "4.0",
                "vulnAvailabilityImpact": "NONE",
                "vulnConfidentialityImpact": "NONE",
                "vulnIntegrityImpact": "LOW",
                "vulnerabilityResponseEffort": "MODERATE"
              },
              "format": "CVSS",
              "scenarios": [
                {
                  "lang": "en",
                  "value": "GENERAL"
                }
              ]
            }
          ],
          "problemTypes": [
            {
              "descriptions": [
                {
                  "cweId": "CWE-250",
                  "description": "CWE-250 Execution with Unnecessary Privileges",
                  "lang": "en",
                  "type": "CWE"
                }
              ]
            }
          ],
          "providerMetadata": {
            "dateUpdated": "2024-10-18T11:59:17.267Z",
            "orgId": "d6c1279f-00f6-4ef7-9217-f89ffe703ec0",
            "shortName": "palo_alto"
          },
          "references": [
            {
              "tags": [
                "vendor-advisory"
              ],
              "url": "https://security.paloaltonetworks.com/CVE-2024-9473"
            },
            {
              "tags": [
                "third-party-advisory",
                "exploit"
              ],
              "url": "https://sec-consult.com/vulnerability-lab/advisory/local-privilege-escalation-via-msi-installer-in-palo-alto-networks-globalprotect/"
            }
          ],
          "solutions": [
            {
              "lang": "en",
              "supportingMedia": [
                {
                  "base64": false,
                  "type": "text/html",
                  "value": "This issue is fixed in GlobalProtect app 6.2.5, and will be fixed in the remaining supported versions of GlobalProtect app listed in the Product Status section. Updates will be published to this advisory as they become available.\u003cbr\u003e\u003cbr\u003eCustomers who want to upgrade should reach out to customer support at \u003ca target=\"_blank\" rel=\"nofollow\" href=\"https://support.paloaltonetworks.com\"\u003ehttps://support.paloaltonetworks.com\u003c/a\u003e.\u003cbr\u003e"
                }
              ],
              "value": "This issue is fixed in GlobalProtect app 6.2.5, and will be fixed in the remaining supported versions of GlobalProtect app listed in the Product Status section. Updates will be published to this advisory as they become available.\n\nCustomers who want to upgrade should reach out to customer support at  https://support.paloaltonetworks.com ."
            }
          ],
          "source": {
            "defect": [
              "GPC-19493",
              "GPC-21211"
            ],
            "discovery": "EXTERNAL"
          },
          "timeline": [
            {
              "lang": "en",
              "time": "2024-10-09T16:00:00.000Z",
              "value": "Initial publication"
            }
          ],
          "title": "GlobalProtect App: Local Privilege Escalation (PE) Vulnerability",
          "x_generator": {
            "engine": "Vulnogram 0.1.0-dev"
          }
        }
      },
      "cveMetadata": {
        "assignerOrgId": "d6c1279f-00f6-4ef7-9217-f89ffe703ec0",
        "assignerShortName": "palo_alto",
        "cveId": "CVE-2024-9473",
        "datePublished": "2024-10-09T17:07:00.981Z",
        "dateReserved": "2024-10-03T11:35:19.552Z",
        "dateUpdated": "2024-10-18T11:59:17.267Z",
        "state": "PUBLISHED"
      },
      "dataType": "CVE_RECORD",
      "dataVersion": "5.1"
    }

    CVE-2024-5915 (GCVE-0-2024-5915)

    Vulnerability from cvelistv5 โ€“ Published: 2024-08-14 16:40 โ€“ Updated: 2024-08-20 13:20
    VLAI
    Title
    GlobalProtect App: Local Privilege Escalation (PE) Vulnerability
    Summary
    A privilege escalation (PE) vulnerability in the Palo Alto Networks GlobalProtect app on Windows devices enables a local user to execute programs with elevated privileges.
    SSVC
    Exploitation: none Automatable: no Technical Impact: total
    CISA Coordinator ยท CISA-ADP (v2.0.3)
    Decision recorded 2024-08-17 03:55 UTC
    CWE
    • CWE-732 - Incorrect Permission Assignment for Critical Resource
    References
    Impacted products
    Vendor Product Version
    Palo Alto Networks GlobalProtect App Affected: 5.1
    Affected: 6.0
    Affected: 6.1 , < 6.1.5 (custom)
    Affected: 6.2 , < 6.2.4 (custom)
    Affected: 6.3 , < 6.3.1 (custom)
    Create a notification for this product.
    paloaltonetworks globalprotect Affected: 5.1
    Affected: 6.0
    Affected: 6.1 , < 6.1.5 (custom)
    Affected: 6.2 , < 6.2.4 (custom)
    Affected: 6.3 , < 6.3.1 (custom)
        cpe:2.3:a:paloaltonetworks:globalprotect:*:*:*:*:*:*:*:*
    Create a notification for this product.
    Date Public
    2024-08-14 16:00
    Show details on NVD website

    {
      "containers": {
        "adp": [
          {
            "affected": [
              {
                "cpes": [
                  "cpe:2.3:a:paloaltonetworks:globalprotect:*:*:*:*:*:*:*:*"
                ],
                "defaultStatus": "unaffected",
                "product": "globalprotect",
                "vendor": "paloaltonetworks",
                "versions": [
                  {
                    "status": "affected",
                    "version": "5.1"
                  },
                  {
                    "status": "affected",
                    "version": "6.0"
                  },
                  {
                    "lessThan": "6.1.5",
                    "status": "affected",
                    "version": "6.1",
                    "versionType": "custom"
                  },
                  {
                    "lessThan": "6.2.4",
                    "status": "affected",
                    "version": "6.2",
                    "versionType": "custom"
                  },
                  {
                    "lessThan": "6.3.1",
                    "status": "affected",
                    "version": "6.3",
                    "versionType": "custom"
                  }
                ]
              }
            ],
            "metrics": [
              {
                "other": {
                  "content": {
                    "id": "CVE-2024-5915",
                    "options": [
                      {
                        "Exploitation": "none"
                      },
                      {
                        "Automatable": "no"
                      },
                      {
                        "Technical Impact": "total"
                      }
                    ],
                    "role": "CISA Coordinator",
                    "timestamp": "2024-08-17T03:55:16.725264Z",
                    "version": "2.0.3"
                  },
                  "type": "ssvc"
                }
              }
            ],
            "providerMetadata": {
              "dateUpdated": "2024-08-20T13:20:36.459Z",
              "orgId": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
              "shortName": "CISA-ADP"
            },
            "title": "CISA ADP Vulnrichment"
          }
        ],
        "cna": {
          "affected": [
            {
              "defaultStatus": "unaffected",
              "platforms": [
                "Windows"
              ],
              "product": "GlobalProtect App",
              "vendor": "Palo Alto Networks",
              "versions": [
                {
                  "status": "affected",
                  "version": "5.1"
                },
                {
                  "status": "affected",
                  "version": "6.0"
                },
                {
                  "changes": [
                    {
                      "at": "6.1.5",
                      "status": "unaffected"
                    }
                  ],
                  "lessThan": "6.1.5",
                  "status": "affected",
                  "version": "6.1",
                  "versionType": "custom"
                },
                {
                  "changes": [
                    {
                      "at": "6.2.4",
                      "status": "unaffected"
                    }
                  ],
                  "lessThan": "6.2.4",
                  "status": "affected",
                  "version": "6.2",
                  "versionType": "custom"
                },
                {
                  "changes": [
                    {
                      "at": "6.3.1",
                      "status": "unaffected"
                    }
                  ],
                  "lessThan": "6.3.1",
                  "status": "affected",
                  "version": "6.3",
                  "versionType": "custom"
                }
              ]
            }
          ],
          "credits": [
            {
              "lang": "en",
              "type": "finder",
              "value": "Ashutosh Gautam/JumpThere"
            },
            {
              "lang": "en",
              "type": "finder",
              "value": "Maciej Miszczyk of Logitech"
            },
            {
              "lang": "en",
              "type": "finder",
              "value": "Will Dormann of ANALYGENCE"
            },
            {
              "lang": "en",
              "type": "finder",
              "value": "Farid Zerrouk"
            },
            {
              "lang": "en",
              "type": "finder",
              "value": "Alaa Kachouh"
            },
            {
              "lang": "en",
              "type": "finder",
              "value": "Ali Jammal"
            }
          ],
          "datePublic": "2024-08-14T16:00:00.000Z",
          "descriptions": [
            {
              "lang": "en",
              "supportingMedia": [
                {
                  "base64": false,
                  "type": "text/html",
                  "value": "A privilege escalation (PE) vulnerability in the Palo Alto Networks GlobalProtect app on Windows devices enables a local user to execute programs with elevated privileges."
                }
              ],
              "value": "A privilege escalation (PE) vulnerability in the Palo Alto Networks GlobalProtect app on Windows devices enables a local user to execute programs with elevated privileges."
            }
          ],
          "exploits": [
            {
              "lang": "en",
              "supportingMedia": [
                {
                  "base64": false,
                  "type": "text/html",
                  "value": "Palo Alto Networks is not aware of any malicious exploitation of this issue.\u003cbr\u003e"
                }
              ],
              "value": "Palo Alto Networks is not aware of any malicious exploitation of this issue."
            }
          ],
          "impacts": [
            {
              "capecId": "CAPEC-233",
              "descriptions": [
                {
                  "lang": "en",
                  "value": "CAPEC-233 Privilege Escalation"
                }
              ]
            }
          ],
          "metrics": [
            {
              "cvssV4_0": {
                "Automatable": "NO",
                "Recovery": "AUTOMATIC",
                "Safety": "NOT_DEFINED",
                "attackComplexity": "LOW",
                "attackRequirements": "PRESENT",
                "attackVector": "LOCAL",
                "baseScore": 5.2,
                "baseSeverity": "MEDIUM",
                "privilegesRequired": "LOW",
                "providerUrgency": "AMBER",
                "subAvailabilityImpact": "HIGH",
                "subConfidentialityImpact": "HIGH",
                "subIntegrityImpact": "HIGH",
                "userInteraction": "NONE",
                "valueDensity": "DIFFUSE",
                "vectorString": "CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:N/VI:L/VA:N/SC:H/SI:H/SA:H/AU:N/R:A/V:D/RE:M/U:Amber",
                "version": "4.0",
                "vulnAvailabilityImpact": "NONE",
                "vulnConfidentialityImpact": "NONE",
                "vulnIntegrityImpact": "LOW",
                "vulnerabilityResponseEffort": "MODERATE"
              },
              "format": "CVSS",
              "scenarios": [
                {
                  "lang": "en",
                  "value": "GENERAL"
                }
              ]
            }
          ],
          "problemTypes": [
            {
              "descriptions": [
                {
                  "cweId": "CWE-732",
                  "description": "CWE-732 Incorrect Permission Assignment for Critical Resource",
                  "lang": "en",
                  "type": "CWE"
                }
              ]
            }
          ],
          "providerMetadata": {
            "dateUpdated": "2024-08-14T16:40:41.840Z",
            "orgId": "d6c1279f-00f6-4ef7-9217-f89ffe703ec0",
            "shortName": "palo_alto"
          },
          "references": [
            {
              "url": "https://security.paloaltonetworks.com/CVE-2024-5915"
            }
          ],
          "solutions": [
            {
              "lang": "en",
              "supportingMedia": [
                {
                  "base64": false,
                  "type": "text/html",
                  "value": "This issue is fixed in GlobalProtect app 5.1.x (ETA: December 2024), GlobalProtect app 6.0.x (ETA: November 2024), GlobalProtect app 6.1.5, GlobalProtect app 6.2.4, GlobalProtect app 6.3.1 (ETA: end of August), and all later GlobalProtect app versions on Windows.\u003cbr\u003e"
                }
              ],
              "value": "This issue is fixed in GlobalProtect app 5.1.x (ETA: December 2024), GlobalProtect app 6.0.x (ETA: November 2024), GlobalProtect app 6.1.5, GlobalProtect app 6.2.4, GlobalProtect app 6.3.1 (ETA: end of August), and all later GlobalProtect app versions on Windows."
            }
          ],
          "source": {
            "defect": [
              "GPC-14958",
              "GPC-19883"
            ],
            "discovery": "EXTERNAL"
          },
          "timeline": [
            {
              "lang": "en",
              "time": "2024-08-14T16:00:00.000Z",
              "value": "Initial publication"
            }
          ],
          "title": "GlobalProtect App: Local Privilege Escalation (PE) Vulnerability",
          "x_generator": {
            "engine": "Vulnogram 0.1.0-dev"
          }
        }
      },
      "cveMetadata": {
        "assignerOrgId": "d6c1279f-00f6-4ef7-9217-f89ffe703ec0",
        "assignerShortName": "palo_alto",
        "cveId": "CVE-2024-5915",
        "datePublished": "2024-08-14T16:40:41.840Z",
        "dateReserved": "2024-06-12T15:27:56.748Z",
        "dateUpdated": "2024-08-20T13:20:36.459Z",
        "state": "PUBLISHED"
      },
      "dataType": "CVE_RECORD",
      "dataVersion": "5.1"
    }

    CVE-2024-5908 (GCVE-0-2024-5908)

    Vulnerability from cvelistv5 โ€“ Published: 2024-06-12 16:28 โ€“ Updated: 2024-08-09 19:08
    VLAI
    Title
    GlobalProtect App: Encrypted Credential Exposure via Log Files
    Summary
    A problem with the Palo Alto Networks GlobalProtect app can result in exposure of encrypted user credentials, used for connecting to GlobalProtect, in application logs. Normally, these application logs are only viewable by local users and are included when generating logs for troubleshooting purposes. This means that these encrypted credentials are exposed to recipients of the application logs.
    SSVC
    Exploitation: none Automatable: no Technical Impact: total
    CISA Coordinator ยท CISA-ADP (v2.0.3)
    Decision recorded 2024-08-09 18:53 UTC
    CWE
    • CWE-532 - Insertion of Sensitive Information into Log File
    References
    Impacted products
    Vendor Product Version
    Palo Alto Networks GlobalProtect App Affected: 5.1.0 , < 5.1.12 (custom)
    Affected: 6.0.0 , < 6.0.8 (custom)
    Affected: 6.1.0 , < 6.1.3 (custom)
    Affected: 6.2.0 , < 6.2.3 (custom)
    Create a notification for this product.
    paloaltonetworks globalprotect Affected: 5.1 , < 5.1.12 (custom)
        cpe:2.3:a:paloaltonetworks:globalprotect:5.1:*:*:*:*:*:*:*
    Create a notification for this product.
    paloaltonetworks globalprotect Affected: 6.0.0 , < 6.0.8 (custom)
        cpe:2.3:a:paloaltonetworks:globalprotect:6.0.0:*:*:*:*:*:*:*
    Create a notification for this product.
    paloaltonetworks globalprotect Affected: 6.1.0 , < 6.1.3 (custom)
        cpe:2.3:a:paloaltonetworks:globalprotect:6.1.0:*:*:*:*:*:*:*
    Create a notification for this product.
    paloaltonetworks globalprotect Affected: 6.2.0 , < 6.2.3 (custom)
        cpe:2.3:a:paloaltonetworks:globalprotect:6.2.0:*:*:*:*:*:*:*
    Create a notification for this product.
    Date Public
    2024-06-12 07:00
    Show details on NVD website

    {
      "containers": {
        "adp": [
          {
            "providerMetadata": {
              "dateUpdated": "2024-08-01T21:25:03.175Z",
              "orgId": "af854a3a-2127-422b-91ae-364da2661108",
              "shortName": "CVE"
            },
            "references": [
              {
                "tags": [
                  "vendor-advisory",
                  "x_transferred"
                ],
                "url": "https://security.paloaltonetworks.com/CVE-2024-5908"
              }
            ],
            "title": "CVE Program Container"
          },
          {
            "affected": [
              {
                "cpes": [
                  "cpe:2.3:a:paloaltonetworks:globalprotect:5.1:*:*:*:*:*:*:*"
                ],
                "defaultStatus": "unaffected",
                "product": "globalprotect",
                "vendor": "paloaltonetworks",
                "versions": [
                  {
                    "lessThan": "5.1.12",
                    "status": "affected",
                    "version": "5.1",
                    "versionType": "custom"
                  }
                ]
              },
              {
                "cpes": [
                  "cpe:2.3:a:paloaltonetworks:globalprotect:6.0.0:*:*:*:*:*:*:*"
                ],
                "defaultStatus": "unaffected",
                "product": "globalprotect",
                "vendor": "paloaltonetworks",
                "versions": [
                  {
                    "lessThan": "6.0.8",
                    "status": "affected",
                    "version": "6.0.0",
                    "versionType": "custom"
                  }
                ]
              },
              {
                "cpes": [
                  "cpe:2.3:a:paloaltonetworks:globalprotect:6.1.0:*:*:*:*:*:*:*"
                ],
                "defaultStatus": "unaffected",
                "product": "globalprotect",
                "vendor": "paloaltonetworks",
                "versions": [
                  {
                    "lessThan": "6.1.3",
                    "status": "affected",
                    "version": "6.1.0",
                    "versionType": "custom"
                  }
                ]
              },
              {
                "cpes": [
                  "cpe:2.3:a:paloaltonetworks:globalprotect:6.2.0:*:*:*:*:*:*:*"
                ],
                "defaultStatus": "unaffected",
                "product": "globalprotect",
                "vendor": "paloaltonetworks",
                "versions": [
                  {
                    "lessThan": "6.2.3",
                    "status": "affected",
                    "version": "6.2.0",
                    "versionType": "custom"
                  }
                ]
              }
            ],
            "metrics": [
              {
                "other": {
                  "content": {
                    "id": "CVE-2024-5908",
                    "options": [
                      {
                        "Exploitation": "none"
                      },
                      {
                        "Automatable": "no"
                      },
                      {
                        "Technical Impact": "total"
                      }
                    ],
                    "role": "CISA Coordinator",
                    "timestamp": "2024-08-09T18:53:54.949374Z",
                    "version": "2.0.3"
                  },
                  "type": "ssvc"
                }
              }
            ],
            "providerMetadata": {
              "dateUpdated": "2024-08-09T19:08:25.260Z",
              "orgId": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
              "shortName": "CISA-ADP"
            },
            "title": "CISA ADP Vulnrichment"
          }
        ],
        "cna": {
          "affected": [
            {
              "defaultStatus": "unaffected",
              "product": "GlobalProtect App",
              "vendor": "Palo Alto Networks",
              "versions": [
                {
                  "changes": [
                    {
                      "at": "5.1.12",
                      "status": "unaffected"
                    }
                  ],
                  "lessThan": "5.1.12",
                  "status": "affected",
                  "version": "5.1.0",
                  "versionType": "custom"
                },
                {
                  "changes": [
                    {
                      "at": "6.0.8",
                      "status": "unaffected"
                    }
                  ],
                  "lessThan": "6.0.8",
                  "status": "affected",
                  "version": "6.0.0",
                  "versionType": "custom"
                },
                {
                  "changes": [
                    {
                      "at": "6.1.3",
                      "status": "unaffected"
                    }
                  ],
                  "lessThan": "6.1.3",
                  "status": "affected",
                  "version": "6.1.0",
                  "versionType": "custom"
                },
                {
                  "changes": [
                    {
                      "at": "6.2.3",
                      "status": "unaffected"
                    }
                  ],
                  "lessThan": "6.2.3",
                  "status": "affected",
                  "version": "6.2.0",
                  "versionType": "custom"
                }
              ]
            }
          ],
          "credits": [
            {
              "lang": "en",
              "type": "finder",
              "value": "Palo Alto Networks thanks Denis Faiustov and Ruslan Sayfiev of GMO Cybersecurity by IERAE for discovering and reporting this issue."
            }
          ],
          "datePublic": "2024-06-12T07:00:00.000Z",
          "descriptions": [
            {
              "lang": "en",
              "supportingMedia": [
                {
                  "base64": false,
                  "type": "text/html",
                  "value": "\u003cp\u003eA problem with the Palo Alto Networks GlobalProtect app can result in exposure of encrypted user credentials, used for connecting to GlobalProtect, in application logs. Normally, these application logs are only viewable by local users and are included when generating logs for troubleshooting purposes. This means that these encrypted credentials are exposed to recipients of the application logs.\u003c/p\u003e"
                }
              ],
              "value": "A problem with the Palo Alto Networks GlobalProtect app can result in exposure of encrypted user credentials, used for connecting to GlobalProtect, in application logs. Normally, these application logs are only viewable by local users and are included when generating logs for troubleshooting purposes. This means that these encrypted credentials are exposed to recipients of the application logs."
            }
          ],
          "exploits": [
            {
              "lang": "en",
              "supportingMedia": [
                {
                  "base64": false,
                  "type": "text/html",
                  "value": "\u003cp\u003ePalo Alto Networks is not aware of any malicious exploitation of this issue.\u003c/p\u003e"
                }
              ],
              "value": "Palo Alto Networks is not aware of any malicious exploitation of this issue."
            }
          ],
          "impacts": [
            {
              "capecId": "CAPEC-150",
              "descriptions": [
                {
                  "lang": "en",
                  "value": "CAPEC-150 Collect Data from Common Resource Locations"
                }
              ]
            }
          ],
          "metrics": [
            {
              "cvssV4_0": {
                "Automatable": "NO",
                "Recovery": "USER",
                "Safety": "NOT_DEFINED",
                "attackComplexity": "LOW",
                "attackRequirements": "PRESENT",
                "attackVector": "NETWORK",
                "baseScore": 5.5,
                "baseSeverity": "MEDIUM",
                "privilegesRequired": "NONE",
                "providerUrgency": "AMBER",
                "subAvailabilityImpact": "HIGH",
                "subConfidentialityImpact": "HIGH",
                "subIntegrityImpact": "HIGH",
                "userInteraction": "ACTIVE",
                "valueDensity": "DIFFUSE",
                "vectorString": "CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:A/VC:L/VI:N/VA:N/SC:H/SI:H/SA:H/AU:N/R:U/V:D/RE:M/U:Amber",
                "version": "4.0",
                "vulnAvailabilityImpact": "NONE",
                "vulnConfidentialityImpact": "LOW",
                "vulnIntegrityImpact": "NONE",
                "vulnerabilityResponseEffort": "MODERATE"
              },
              "format": "CVSS",
              "scenarios": [
                {
                  "lang": "en",
                  "value": "GENERAL"
                }
              ]
            }
          ],
          "problemTypes": [
            {
              "descriptions": [
                {
                  "cweId": "CWE-532",
                  "description": "CWE-532: Insertion of Sensitive Information into Log File",
                  "lang": "en",
                  "type": "CWE"
                }
              ]
            }
          ],
          "providerMetadata": {
            "dateUpdated": "2024-06-12T16:28:08.131Z",
            "orgId": "d6c1279f-00f6-4ef7-9217-f89ffe703ec0",
            "shortName": "palo_alto"
          },
          "references": [
            {
              "tags": [
                "vendor-advisory"
              ],
              "url": "https://security.paloaltonetworks.com/CVE-2024-5908"
            }
          ],
          "solutions": [
            {
              "lang": "en",
              "supportingMedia": [
                {
                  "base64": false,
                  "type": "text/html",
                  "value": "\u003cp\u003eThis issue is fixed in GlobalProtect app 5.1.12, GlobalProtect app 6.0.8, GlobalProtect app 6.1.3, GlobalProtect app 6.2.3, and all later GlobalProtect app versions.\u003c/p\u003e\u003cp\u003eCustomers looking to protect against the impact of this encrypted password disclosure should first delete PanGPS.log files from the GlobalProtect installation directory on all endpoints and then force a rotation of user passwords that are used to connect to GlobalProtect.\u003c/p\u003e"
                }
              ],
              "value": "This issue is fixed in GlobalProtect app 5.1.12, GlobalProtect app 6.0.8, GlobalProtect app 6.1.3, GlobalProtect app 6.2.3, and all later GlobalProtect app versions.\n\nCustomers looking to protect against the impact of this encrypted password disclosure should first delete PanGPS.log files from the GlobalProtect installation directory on all endpoints and then force a rotation of user passwords that are used to connect to GlobalProtect."
            }
          ],
          "source": {
            "defect": [
              "GPC-18597"
            ],
            "discovery": "EXTERNAL"
          },
          "timeline": [
            {
              "lang": "en",
              "time": "2024-06-12T16:00:00.000Z",
              "value": "Initial publication"
            }
          ],
          "title": "GlobalProtect App: Encrypted Credential Exposure via Log Files",
          "x_generator": {
            "engine": "vulnogram 0.1.0-rc1"
          },
          "x_legacyV4Record": {
            "CNA_private": {
              "Priority": "normal",
              "STATE": "review",
              "TYPE": "advisory",
              "affectsSummary": {
                "affected": [
                  "\u003c 6.2.3",
                  "\u003c 6.1.3",
                  "\u003c 6.0.8",
                  "\u003c 5.1.12"
                ],
                "appliesTo": [
                  "GlobalProtect App 6.2",
                  "GlobalProtect App 6.1",
                  "GlobalProtect App 6.0",
                  "GlobalProtect App 5.1"
                ],
                "product_versions": [
                  "GlobalProtect App 6.2",
                  "GlobalProtect App 6.1",
                  "GlobalProtect App 6.0",
                  "GlobalProtect App 5.1"
                ],
                "unaffected": [
                  "\u003e= 6.2.3",
                  "\u003e= 6.1.3",
                  "\u003e= 6.0.8",
                  "\u003e= 5.1.12"
                ],
                "unknown": [
                  "",
                  "",
                  "",
                  ""
                ]
              },
              "owner": "carjones",
              "publish": {
                "month": "06",
                "year": "2024",
                "ym": "2024-06"
              },
              "share_with_CVE": true,
              "show_cvss": true
            },
            "CVE_data_meta": {
              "ASSIGNER": "psirt@paloaltonetworks.com",
              "DATE_PUBLIC": "2024-06-12T16:00:00.000Z",
              "ID": "CVE-2023-case-GPC-18597",
              "STATE": "PUBLIC",
              "TITLE": "GlobalProtect App: Encrypted Credential Exposure via Log Files"
            },
            "affects": {
              "vendor": {
                "vendor_data": [
                  {
                    "product": {
                      "product_data": [
                        {
                          "product_name": "GlobalProtect App",
                          "version": {
                            "version_data": [
                              {
                                "version_affected": "\u003c",
                                "version_name": "5.1",
                                "version_value": "5.1.12"
                              },
                              {
                                "version_affected": "\u003c",
                                "version_name": "6.0",
                                "version_value": "6.0.8"
                              },
                              {
                                "version_affected": "\u003c",
                                "version_name": "6.1",
                                "version_value": "6.1.3"
                              },
                              {
                                "version_affected": "\u003c",
                                "version_name": "6.2",
                                "version_value": "6.2.3"
                              },
                              {
                                "version_affected": "!\u003e=",
                                "version_name": "5.1",
                                "version_value": "5.1.12"
                              },
                              {
                                "version_affected": "!\u003e=",
                                "version_name": "6.0",
                                "version_value": "6.0.8"
                              },
                              {
                                "version_affected": "!\u003e=",
                                "version_name": "6.1",
                                "version_value": "6.1.3"
                              },
                              {
                                "version_affected": "!\u003e=",
                                "version_name": "6.2",
                                "version_value": "6.2.3"
                              }
                            ]
                          }
                        }
                      ]
                    },
                    "vendor_name": "Palo Alto Networks"
                  }
                ]
              }
            },
            "credit": [
              {
                "lang": "eng",
                "value": "Palo Alto Networks thanks Denis Faiustov and Ruslan Sayfiev of GMO Cybersecurity by IERAE for discovering and reporting this issue."
              }
            ],
            "data_format": "MITRE",
            "data_type": "CVE",
            "data_version": "4.0",
            "description": {
              "description_data": [
                {
                  "lang": "eng",
                  "value": "A problem with the Palo Alto Networks GlobalProtect app can result in exposure of encrypted user credentials, used for connecting to GlobalProtect, in application logs. Normally, these application logs are only viewable by local users and are included when generating logs for troubleshooting purposes. This means that these encrypted credentials are exposed to recipients of the application logs."
                }
              ]
            },
            "exploit": [
              {
                "lang": "en",
                "value": "Palo Alto Networks is not aware of any malicious exploitation of this issue."
              }
            ],
            "generator": {
              "engine": "vulnogram 0.1.0-rc1"
            },
            "impact": {
              "cvss": {
                "Automatable": "NO",
                "Recovery": "USER",
                "Safety": "NOT_DEFINED",
                "attackComplexity": "LOW",
                "attackRequirements": "PRESENT",
                "attackVector": "NETWORK",
                "baseScore": 5.5,
                "baseSeverity": "MEDIUM",
                "privilegesRequired": "NONE",
                "providerUrgency": "AMBER",
                "subAvailabilityImpact": "HIGH",
                "subConfidentialityImpact": "HIGH",
                "subIntegrityImpact": "HIGH",
                "userInteraction": "ACTIVE",
                "valueDensity": "DIFFUSE",
                "vectorString": "CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:A/VC:L/VI:N/VA:N/SC:H/SI:H/SA:H/AU:N/R:U/V:D/RE:M/U:Amber",
                "version": "4.0",
                "vulnAvailabilityImpact": "NONE",
                "vulnConfidentialityImpact": "LOW",
                "vulnIntegrityImpact": "NONE",
                "vulnerabilityResponseEffort": "MODERATE"
              }
            },
            "problemtype": {
              "problemtype_data": [
                {
                  "description": [
                    {
                      "lang": "eng",
                      "value": "CWE-532: Insertion of Sensitive Information into Log File"
                    }
                  ]
                }
              ]
            },
            "references": {
              "reference_data": [
                {
                  "refsource": "CONFIRM",
                  "url": "https://security.paloaltonetworks.com/CVE-2023-case-GPC-18597"
                }
              ]
            },
            "solution": [
              {
                "lang": "en",
                "value": "This issue is fixed in GlobalProtect app 5.1.12, GlobalProtect app 6.0.8, GlobalProtect app 6.1.3, GlobalProtect app 6.2.3, and all later GlobalProtect app versions.Customers looking to protect against the impact of this encrypted password disclosure should first delete PanGPS.log files from the GlobalProtect installation directory on all endpoints and then force a rotation of user passwords that are used to connect to GlobalProtect."
              }
            ],
            "source": {
              "defect": [
                "GPC-18597"
              ],
              "discovery": "EXTERNAL"
            },
            "timeline": [
              {
                "lang": "en",
                "time": "2024-06-12T00:00:00.000Z",
                "value": "Initial publication"
              }
            ],
            "x_advisoryEoL": false
          }
        }
      },
      "cveMetadata": {
        "assignerOrgId": "d6c1279f-00f6-4ef7-9217-f89ffe703ec0",
        "assignerShortName": "palo_alto",
        "cveId": "CVE-2024-5908",
        "datePublished": "2024-06-12T16:28:08.131Z",
        "dateReserved": "2024-06-12T15:27:55.490Z",
        "dateUpdated": "2024-08-09T19:08:25.260Z",
        "state": "PUBLISHED"
      },
      "dataType": "CVE_RECORD",
      "dataVersion": "5.1"
    }

    CVE-2024-2432 (GCVE-0-2024-2432)

    Vulnerability from cvelistv5 โ€“ Published: 2024-03-13 17:51 โ€“ Updated: 2024-08-28 15:14
    VLAI
    Title
    GlobalProtect App: Local Privilege Escalation (PE) Vulnerability
    Summary
    A privilege escalation (PE) vulnerability in the Palo Alto Networks GlobalProtect app on Windows devices enables a local user to execute programs with elevated privileges. However, execution requires that the local user is able to successfully exploit a race condition.
    SSVC
    Exploitation: none Automatable: no Technical Impact: total
    CISA Coordinator ยท CISA-ADP (v2.0.3)
    Decision recorded 2024-03-13 19:57 UTC
    CWE
    • CWE-269 - Improper Privilege Management
    References
    Impacted products
    Vendor Product Version
    Palo Alto Networks GlobalProtect App Affected: 5.1 , < 5.1.12 (custom)
    Affected: 6.0 , < 6.0.8 (custom)
    Affected: 6.1 , < 6.1.2 (custom)
    Affected: 6.2 , < 6.2.1 (custom)
    Create a notification for this product.
    paloaltonetworks globalprotect Affected: 5.1 , < 5.1.12 (custom)
    Affected: 6.0 , < 6.0.8 (custom)
    Affected: 6.1 , < 6.1.2 (custom)
    Affected: 6.2 , < 6.2.1 (custom)
        cpe:2.3:a:paloaltonetworks:globalprotect:*:*:*:*:*:*:*:*
    Create a notification for this product.
    Date Public
    2024-03-13 16:00
    Show details on NVD website

    {
      "containers": {
        "adp": [
          {
            "providerMetadata": {
              "dateUpdated": "2024-08-01T19:11:53.524Z",
              "orgId": "af854a3a-2127-422b-91ae-364da2661108",
              "shortName": "CVE"
            },
            "references": [
              {
                "tags": [
                  "x_transferred"
                ],
                "url": "https://security.paloaltonetworks.com/CVE-2024-2432"
              }
            ],
            "title": "CVE Program Container"
          },
          {
            "affected": [
              {
                "cpes": [
                  "cpe:2.3:a:paloaltonetworks:globalprotect:*:*:*:*:*:*:*:*"
                ],
                "defaultStatus": "unaffected",
                "product": "globalprotect",
                "vendor": "paloaltonetworks",
                "versions": [
                  {
                    "lessThan": "5.1.12",
                    "status": "affected",
                    "version": "5.1",
                    "versionType": "custom"
                  },
                  {
                    "lessThan": "6.0.8",
                    "status": "affected",
                    "version": "6.0",
                    "versionType": "custom"
                  },
                  {
                    "lessThan": "6.1.2",
                    "status": "affected",
                    "version": "6.1",
                    "versionType": "custom"
                  },
                  {
                    "lessThan": "6.2.1",
                    "status": "affected",
                    "version": "6.2",
                    "versionType": "custom"
                  }
                ]
              }
            ],
            "metrics": [
              {
                "other": {
                  "content": {
                    "id": "CVE-2024-2432",
                    "options": [
                      {
                        "Exploitation": "none"
                      },
                      {
                        "Automatable": "no"
                      },
                      {
                        "Technical Impact": "total"
                      }
                    ],
                    "role": "CISA Coordinator",
                    "timestamp": "2024-03-13T19:57:08.397529Z",
                    "version": "2.0.3"
                  },
                  "type": "ssvc"
                }
              }
            ],
            "providerMetadata": {
              "dateUpdated": "2024-08-28T15:14:21.571Z",
              "orgId": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
              "shortName": "CISA-ADP"
            },
            "title": "CISA ADP Vulnrichment"
          }
        ],
        "cna": {
          "affected": [
            {
              "defaultStatus": "unaffected",
              "platforms": [
                "Windows"
              ],
              "product": "GlobalProtect App",
              "vendor": "Palo Alto Networks",
              "versions": [
                {
                  "changes": [
                    {
                      "at": "5.1.12",
                      "status": "unaffected"
                    }
                  ],
                  "lessThan": "5.1.12",
                  "status": "affected",
                  "version": "5.1",
                  "versionType": "custom"
                },
                {
                  "changes": [
                    {
                      "at": "6.0.8",
                      "status": "unaffected"
                    }
                  ],
                  "lessThan": "6.0.8",
                  "status": "affected",
                  "version": "6.0",
                  "versionType": "custom"
                },
                {
                  "changes": [
                    {
                      "at": "6.1.2",
                      "status": "unaffected"
                    }
                  ],
                  "lessThan": "6.1.2",
                  "status": "affected",
                  "version": "6.1",
                  "versionType": "custom"
                },
                {
                  "changes": [
                    {
                      "at": "6.2.1",
                      "status": "unaffected"
                    }
                  ],
                  "lessThan": "6.2.1",
                  "status": "affected",
                  "version": "6.2",
                  "versionType": "custom"
                }
              ]
            }
          ],
          "credits": [
            {
              "lang": "en",
              "type": "finder",
              "value": "Palo Alto Networks thanks Erwin Chan for discovering and reporting this issue."
            }
          ],
          "datePublic": "2024-03-13T16:00:00.000Z",
          "descriptions": [
            {
              "lang": "en",
              "supportingMedia": [
                {
                  "base64": false,
                  "type": "text/html",
                  "value": "A privilege escalation (PE) vulnerability in the Palo Alto Networks GlobalProtect app on Windows devices enables a local user to execute programs with elevated privileges. However, execution requires that the local user is able to successfully exploit a race condition."
                }
              ],
              "value": "A privilege escalation (PE) vulnerability in the Palo Alto Networks GlobalProtect app on Windows devices enables a local user to execute programs with elevated privileges. However, execution requires that the local user is able to successfully exploit a race condition."
            }
          ],
          "exploits": [
            {
              "lang": "en",
              "supportingMedia": [
                {
                  "base64": false,
                  "type": "text/html",
                  "value": "Palo Alto Networks is not aware of any malicious exploitation of this issue.\u003cbr\u003e"
                }
              ],
              "value": "Palo Alto Networks is not aware of any malicious exploitation of this issue.\n"
            }
          ],
          "metrics": [
            {
              "cvssV3_1": {
                "attackComplexity": "HIGH",
                "attackVector": "LOCAL",
                "availabilityImpact": "LOW",
                "baseScore": 4.5,
                "baseSeverity": "MEDIUM",
                "confidentialityImpact": "LOW",
                "integrityImpact": "LOW",
                "privilegesRequired": "LOW",
                "scope": "UNCHANGED",
                "userInteraction": "NONE",
                "vectorString": "CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:L/I:L/A:L",
                "version": "3.1"
              },
              "format": "CVSS",
              "scenarios": [
                {
                  "lang": "en",
                  "value": "GENERAL"
                }
              ]
            }
          ],
          "problemTypes": [
            {
              "descriptions": [
                {
                  "cweId": "CWE-269",
                  "description": "CWE-269 Improper Privilege Management",
                  "lang": "en",
                  "type": "CWE"
                }
              ]
            }
          ],
          "providerMetadata": {
            "dateUpdated": "2024-03-13T17:51:33.908Z",
            "orgId": "d6c1279f-00f6-4ef7-9217-f89ffe703ec0",
            "shortName": "palo_alto"
          },
          "references": [
            {
              "url": "https://security.paloaltonetworks.com/CVE-2024-2432"
            }
          ],
          "solutions": [
            {
              "lang": "en",
              "supportingMedia": [
                {
                  "base64": false,
                  "type": "text/html",
                  "value": "This issue is fixed in GlobalProtect app 5.1.12, GlobalProtect app 6.0.8, GlobalProtect app 6.1.2, GlobalProtect app 6.2.1, and all later GlobalProtect app versions  on Windows.\u003cbr\u003e"
                }
              ],
              "value": "This issue is fixed in GlobalProtect app 5.1.12, GlobalProtect app 6.0.8, GlobalProtect app 6.1.2, GlobalProtect app 6.2.1, and all later GlobalProtect app versions  on Windows.\n"
            }
          ],
          "source": {
            "defect": [
              "GPC-18129"
            ],
            "discovery": "EXTERNAL"
          },
          "timeline": [
            {
              "lang": "en",
              "time": "2024-03-13T16:00:00.000Z",
              "value": "Initial publication"
            }
          ],
          "title": "GlobalProtect App: Local Privilege Escalation (PE) Vulnerability",
          "x_generator": {
            "engine": "Vulnogram 0.1.0-dev"
          }
        }
      },
      "cveMetadata": {
        "assignerOrgId": "d6c1279f-00f6-4ef7-9217-f89ffe703ec0",
        "assignerShortName": "palo_alto",
        "cveId": "CVE-2024-2432",
        "datePublished": "2024-03-13T17:51:33.908Z",
        "dateReserved": "2024-03-13T16:19:26.854Z",
        "dateUpdated": "2024-08-28T15:14:21.571Z",
        "state": "PUBLISHED"
      },
      "dataType": "CVE_RECORD",
      "dataVersion": "5.1"
    }

    CVE-2024-2431 (GCVE-0-2024-2431)

    Vulnerability from cvelistv5 โ€“ Published: 2024-03-13 17:51 โ€“ Updated: 2024-08-05 13:31
    VLAI
    Title
    GlobalProtect App: Local User Can Disable GlobalProtect
    Summary
    An issue in the Palo Alto Networks GlobalProtect app enables a non-privileged user to disable the GlobalProtect app in configurations that allow a user to disable GlobalProtect with a passcode.
    SSVC
    Exploitation: none Automatable: no Technical Impact: total
    CISA Coordinator ยท CISA-ADP (v2.0.3)
    Decision recorded 2024-03-15 15:20 UTC
    CWE
    • CWE-269 - Improper Privilege Management
    References
    Impacted products
    Vendor Product Version
    Palo Alto Networks GlobalProtect App Affected: 6.0 , < 6.0.4 (custom)
    Affected: 5.1 , < 5.1.12 (custom)
    Affected: 5.2 , < 5.2.13 (custom)
    Affected: 6.1 , < 6.1.1 (custom)
    Unaffected: 6.2
    Create a notification for this product.
    paloaltonetworks globalprotect Affected: 5.1 , < 5.1.12 (custom)
    Affected: 5.2 , < 5.2.13 (custom)
    Affected: 6.0.0 , < 6.0.4 (custom)
    Affected: 6.1.0 , < 6.1.1 (custom)
    Unaffected: 6.2.0
        cpe:2.3:a:paloaltonetworks:globalprotect:5.1:*:*:*:*:*:*:*
        cpe:2.3:a:paloaltonetworks:globalprotect:5.2:*:*:*:*:universal_windows_platform:*:*
        cpe:2.3:a:paloaltonetworks:globalprotect:6.0.0:*:*:*:*:universal_windows_platform:*:*
        cpe:2.3:a:paloaltonetworks:globalprotect:6.1.0:*:*:*:*:universal_windows_platform:*:*
        cpe:2.3:a:paloaltonetworks:globalprotect:6.2.0:*:*:*:*:windows:*:*
    Create a notification for this product.
    Date Public
    2024-03-13 16:00
    Show details on NVD website

    {
      "containers": {
        "adp": [
          {
            "providerMetadata": {
              "dateUpdated": "2024-08-01T19:11:53.593Z",
              "orgId": "af854a3a-2127-422b-91ae-364da2661108",
              "shortName": "CVE"
            },
            "references": [
              {
                "tags": [
                  "x_transferred"
                ],
                "url": "https://security.paloaltonetworks.com/CVE-2024-2431"
              }
            ],
            "title": "CVE Program Container"
          },
          {
            "affected": [
              {
                "cpes": [
                  "cpe:2.3:a:paloaltonetworks:globalprotect:5.1:*:*:*:*:*:*:*",
                  "cpe:2.3:a:paloaltonetworks:globalprotect:5.2:*:*:*:*:universal_windows_platform:*:*",
                  "cpe:2.3:a:paloaltonetworks:globalprotect:6.0.0:*:*:*:*:universal_windows_platform:*:*",
                  "cpe:2.3:a:paloaltonetworks:globalprotect:6.1.0:*:*:*:*:universal_windows_platform:*:*",
                  "cpe:2.3:a:paloaltonetworks:globalprotect:6.2.0:*:*:*:*:windows:*:*"
                ],
                "defaultStatus": "unknown",
                "product": "globalprotect",
                "vendor": "paloaltonetworks",
                "versions": [
                  {
                    "lessThan": "5.1.12",
                    "status": "affected",
                    "version": "5.1",
                    "versionType": "custom"
                  },
                  {
                    "lessThan": "5.2.13",
                    "status": "affected",
                    "version": "5.2",
                    "versionType": "custom"
                  },
                  {
                    "lessThan": "6.0.4",
                    "status": "affected",
                    "version": "6.0.0",
                    "versionType": "custom"
                  },
                  {
                    "lessThan": "6.1.1",
                    "status": "affected",
                    "version": "6.1.0",
                    "versionType": "custom"
                  },
                  {
                    "status": "unaffected",
                    "version": "6.2.0"
                  }
                ]
              }
            ],
            "metrics": [
              {
                "other": {
                  "content": {
                    "id": "CVE-2024-2431",
                    "options": [
                      {
                        "Exploitation": "none"
                      },
                      {
                        "Automatable": "no"
                      },
                      {
                        "Technical Impact": "total"
                      }
                    ],
                    "role": "CISA Coordinator",
                    "timestamp": "2024-03-15T15:20:30.083812Z",
                    "version": "2.0.3"
                  },
                  "type": "ssvc"
                }
              }
            ],
            "providerMetadata": {
              "dateUpdated": "2024-08-05T13:31:26.517Z",
              "orgId": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
              "shortName": "CISA-ADP"
            },
            "title": "CISA ADP Vulnrichment"
          }
        ],
        "cna": {
          "affected": [
            {
              "defaultStatus": "unaffected",
              "product": "GlobalProtect App",
              "vendor": "Palo Alto Networks",
              "versions": [
                {
                  "changes": [
                    {
                      "at": "6.0.4",
                      "status": "unaffected"
                    }
                  ],
                  "lessThan": "6.0.4",
                  "status": "affected",
                  "version": "6.0",
                  "versionType": "custom"
                },
                {
                  "changes": [
                    {
                      "at": "5.1.12",
                      "status": "unaffected"
                    }
                  ],
                  "lessThan": "5.1.12",
                  "status": "affected",
                  "version": "5.1",
                  "versionType": "custom"
                },
                {
                  "changes": [
                    {
                      "at": "5.2.13",
                      "status": "unaffected"
                    }
                  ],
                  "lessThan": "5.2.13",
                  "status": "affected",
                  "version": "5.2",
                  "versionType": "custom"
                },
                {
                  "changes": [
                    {
                      "at": "6.1.1",
                      "status": "unaffected"
                    }
                  ],
                  "lessThan": "6.1.1",
                  "status": "affected",
                  "version": "6.1",
                  "versionType": "custom"
                },
                {
                  "status": "unaffected",
                  "version": "6.2"
                }
              ]
            }
          ],
          "configurations": [
            {
              "lang": "en",
              "supportingMedia": [
                {
                  "base64": false,
                  "type": "text/html",
                  "value": "This is an issue only if \"Allow User to Disable GlobalProtect App\" is set to \"Allow with Passcode\". You should check this setting in your firewall web interface (Network \u003e GlobalProtect \u003e Portals \u003e (portal-config) \u003e Agent \u003e (agent-config) \u003e App) and take the appropriate actions as needed."
                }
              ],
              "value": "This is an issue only if \"Allow User to Disable GlobalProtect App\" is set to \"Allow with Passcode\". You should check this setting in your firewall web interface (Network \u003e GlobalProtect \u003e Portals \u003e (portal-config) \u003e Agent \u003e (agent-config) \u003e App) and take the appropriate actions as needed."
            }
          ],
          "credits": [
            {
              "lang": "en",
              "type": "finder",
              "value": "Palo Alto Networks thanks AIG Red Team and Stephen Collyer for discovering and reporting this issue."
            }
          ],
          "datePublic": "2024-03-13T16:00:00.000Z",
          "descriptions": [
            {
              "lang": "en",
              "supportingMedia": [
                {
                  "base64": false,
                  "type": "text/html",
                  "value": "An issue in the Palo Alto Networks GlobalProtect app enables a non-privileged user to disable the GlobalProtect app in configurations that allow a user to disable GlobalProtect with a passcode."
                }
              ],
              "value": "An issue in the Palo Alto Networks GlobalProtect app enables a non-privileged user to disable the GlobalProtect app in configurations that allow a user to disable GlobalProtect with a passcode."
            }
          ],
          "exploits": [
            {
              "lang": "en",
              "supportingMedia": [
                {
                  "base64": false,
                  "type": "text/html",
                  "value": "Palo Alto Networks is not aware of any malicious exploitation of this issue.\u003cbr\u003e"
                }
              ],
              "value": "Palo Alto Networks is not aware of any malicious exploitation of this issue.\n"
            }
          ],
          "metrics": [
            {
              "cvssV3_1": {
                "attackComplexity": "LOW",
                "attackVector": "LOCAL",
                "availabilityImpact": "HIGH",
                "baseScore": 5.5,
                "baseSeverity": "MEDIUM",
                "confidentialityImpact": "NONE",
                "integrityImpact": "NONE",
                "privilegesRequired": "LOW",
                "scope": "UNCHANGED",
                "userInteraction": "NONE",
                "vectorString": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H",
                "version": "3.1"
              },
              "format": "CVSS",
              "scenarios": [
                {
                  "lang": "en",
                  "value": "GENERAL"
                }
              ]
            }
          ],
          "problemTypes": [
            {
              "descriptions": [
                {
                  "cweId": "CWE-269",
                  "description": "CWE-269 Improper Privilege Management",
                  "lang": "en",
                  "type": "CWE"
                }
              ]
            }
          ],
          "providerMetadata": {
            "dateUpdated": "2024-03-13T17:51:17.735Z",
            "orgId": "d6c1279f-00f6-4ef7-9217-f89ffe703ec0",
            "shortName": "palo_alto"
          },
          "references": [
            {
              "url": "https://security.paloaltonetworks.com/CVE-2024-2431"
            }
          ],
          "solutions": [
            {
              "lang": "en",
              "supportingMedia": [
                {
                  "base64": false,
                  "type": "text/html",
                  "value": "This issue is fixed in GlobalProtect app 5.1.12, GlobalProtect app 5.2.13, GlobalProtect app 6.0.4, GlobalProtect app 6.1.1, and all later GlobalProtect app versions.\u003cbr\u003e"
                }
              ],
              "value": "This issue is fixed in GlobalProtect app 5.1.12, GlobalProtect app 5.2.13, GlobalProtect app 6.0.4, GlobalProtect app 6.1.1, and all later GlobalProtect app versions.\n"
            }
          ],
          "source": {
            "defect": [
              "GPC-15349"
            ],
            "discovery": "EXTERNAL"
          },
          "timeline": [
            {
              "lang": "en",
              "time": "2024-03-13T16:00:00.000Z",
              "value": "Initial publication"
            }
          ],
          "title": "GlobalProtect App: Local User Can Disable GlobalProtect",
          "workarounds": [
            {
              "lang": "en",
              "supportingMedia": [
                {
                  "base64": false,
                  "type": "text/html",
                  "value": "You can mitigate this issue by setting \"Allow User to Disable GlobalProtect App\" to \"Disallow\" or \"Allow with Ticket.\"\u003cbr\u003e"
                }
              ],
              "value": "You can mitigate this issue by setting \"Allow User to Disable GlobalProtect App\" to \"Disallow\" or \"Allow with Ticket.\"\n"
            }
          ],
          "x_generator": {
            "engine": "Vulnogram 0.1.0-dev"
          }
        }
      },
      "cveMetadata": {
        "assignerOrgId": "d6c1279f-00f6-4ef7-9217-f89ffe703ec0",
        "assignerShortName": "palo_alto",
        "cveId": "CVE-2024-2431",
        "datePublished": "2024-03-13T17:51:17.735Z",
        "dateReserved": "2024-03-13T16:19:25.624Z",
        "dateUpdated": "2024-08-05T13:31:26.517Z",
        "state": "PUBLISHED"
      },
      "dataType": "CVE_RECORD",
      "dataVersion": "5.1"
    }