Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-ccr5-hmvm-37q5

Опубликовано: 27 нояб. 2024
Источник: github
Github: Не прошло ревью
CVSS4: 7.1
CVSS3: 8.8

Описание

An insufficient certification validation issue in the Palo Alto Networks GlobalProtect app enables attackers to connect the GlobalProtect app to arbitrary servers. This can enable a local non-administrative operating system user or an attacker on the same subnet to install malicious root certificates on the endpoint and subsequently install malicious software signed by the malicious root certificates on that endpoint.

GlobalProtect App for Android is under evaluation. Please subscribe to our RSS feed https://security.paloaltonetworks.com/rss.xml to be alerted to new updates to this and other advisories.

An insufficient certification validation issue in the Palo Alto Networks GlobalProtect app enables attackers to connect the GlobalProtect app to arbitrary servers. This can enable a local non-administrative operating system user or an attacker on the same subnet to install malicious root certificates on the endpoint and subsequently install malicious software signed by the malicious root certificates on that endpoint.

GlobalProtect App for Android is under evaluation. Please subscribe to our RSS feed https://security.paloaltonetworks.com/rss.xml to be alerted to new updates to this and other advisories.

EPSS

Процентиль: 51%
0.00277
Низкий

7.1 High

CVSS4

8.8 High

CVSS3

Дефекты

CWE-295

Связанные уязвимости

CVSS3: 8.8
nvd
около 1 года назад

An insufficient certification validation issue in the Palo Alto Networks GlobalProtect app enables attackers to connect the GlobalProtect app to arbitrary servers. This can enable a local non-administrative operating system user or an attacker on the same subnet to install malicious root certificates on the endpoint and subsequently install malicious software signed by the malicious root certificates on that endpoint. Please subscribe to our RSS feed https://security.paloaltonetworks.com/rss.xml to be alerted to new updates to this and other advisories.

CVSS3: 7.3
fstec
больше 1 года назад

Уязвимость компонента Root Certificate Handler программного средства для обеспечения безопасного удаленного доступа к данным Palo Alto Networks GlobalProtect App, позволяющая нарушителю повысить свои привилегии

EPSS

Процентиль: 51%
0.00277
Низкий

7.1 High

CVSS4

8.8 High

CVSS3

Дефекты

CWE-295