Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-j4r7-wx6h-r3mw

Опубликовано: 13 мая 2022
Источник: github
Github: Не прошло ревью

Описание

Palo Alto Networks GlobalProtect before 1.1.7, and NetConnect, does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof portal servers and obtain sensitive information via a crafted certificate.

Palo Alto Networks GlobalProtect before 1.1.7, and NetConnect, does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof portal servers and obtain sensitive information via a crafted certificate.

EPSS

Процентиль: 45%
0.00229
Низкий

Связанные уязвимости

nvd
больше 12 лет назад

Palo Alto Networks GlobalProtect before 1.1.7, and NetConnect, does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof portal servers and obtain sensitive information via a crafted certificate.

EPSS

Процентиль: 45%
0.00229
Низкий