CVE-2024-8691
Sept. 12, 2024, 12:35 p.m.
Tags
Product(s) Impacted
Palo Alto Networks PAN-OS software
Description
A vulnerability in the GlobalProtect portal in Palo Alto Networks PAN-OS software enables a malicious authenticated GlobalProtect user to impersonate another GlobalProtect user. Active GlobalProtect users impersonated by an attacker who is exploiting this vulnerability are disconnected from GlobalProtect. Upon exploitation, PAN-OS logs indicate that the impersonated user authenticated to GlobalProtect, which hides the identity of the attacker.
Weaknesses
CWE-863
Incorrect Authorization
The product performs an authorization check when an actor attempts to access a resource or perform an action, but it does not correctly perform the check. This allows attackers to bypass intended access restrictions.
CWE ID: 863Date
Published: Sept. 11, 2024, 5:15 p.m.
Last Modified: Sept. 12, 2024, 12:35 p.m.
Status : Undergoing Analysis
CVE has been recently published to the CVE List and has been received by the NVD.
More infoSource
psirt@paloaltonetworks.com