CVE-2024-8691
Sept. 12, 2024, 12:35 p.m.
None
No Score
Description
A vulnerability in the GlobalProtect portal in Palo Alto Networks PAN-OS software enables a malicious authenticated GlobalProtect user to impersonate another GlobalProtect user. Active GlobalProtect users impersonated by an attacker who is exploiting this vulnerability are disconnected from GlobalProtect. Upon exploitation, PAN-OS logs indicate that the impersonated user authenticated to GlobalProtect, which hides the identity of the attacker.
Product(s) Impacted
Product | Versions |
---|---|
Palo Alto Networks PAN-OS software |
|
Weaknesses
Common security weaknesses mapped to this vulnerability.
CWE-863
Incorrect Authorization
The product performs an authorization check when an actor attempts to access a resource or perform an action, but it does not correctly perform the check. This allows attackers to bypass intended access restrictions.
Tags
Timeline
Published: Sept. 11, 2024, 5:15 p.m.
Last Modified: Sept. 12, 2024, 12:35 p.m.
Last Modified: Sept. 12, 2024, 12:35 p.m.
Status : Undergoing Analysis
CVE has been recently published to the CVE List and has been received by the NVD.
More infoSource
psirt@paloaltonetworks.com
*Disclaimer: Some vulnerabilities do not have an associated CPE. To enhance the data, we use AI to infer CPEs based on CVE details. This is an automated process and might not always be accurate.