Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-v76x-c74h-522h

Опубликовано: 13 авг. 2025
Источник: github
Github: Не прошло ревью
CVSS4: 5.3

Описание

An insufficient certificate validation issue in the Palo Alto Networks GlobalProtect™ app enables attackers to connect the GlobalProtect app to arbitrary servers. This can enable a local non-administrative operating system user or an attacker on the same subnet to install malicious root certificates on the endpoint and subsequently install malicious software signed by the malicious root certificates on that endpoint.

An insufficient certificate validation issue in the Palo Alto Networks GlobalProtect™ app enables attackers to connect the GlobalProtect app to arbitrary servers. This can enable a local non-administrative operating system user or an attacker on the same subnet to install malicious root certificates on the endpoint and subsequently install malicious software signed by the malicious root certificates on that endpoint.

EPSS

Процентиль: 3%
0.00017
Низкий

5.3 Medium

CVSS4

Дефекты

CWE-295

Связанные уязвимости

nvd
6 месяцев назад

An insufficient certificate validation issue in the Palo Alto Networks GlobalProtect™ app enables attackers to connect the GlobalProtect app to arbitrary servers. This can enable a local non-administrative operating system user or an attacker on the same subnet to install malicious root certificates on the endpoint and subsequently install malicious software signed by the malicious root certificates on that endpoint.

CVSS3: 5
fstec
11 месяцев назад

Уязвимость программного средства для обеспечения безопасного удаленного доступа к данным Palo Alto Networks GlobalProtect App, связанная с ошибками процедуры подтверждения подлинности сертификата, позволяющая нарушителю создать вредоносный сертификат

EPSS

Процентиль: 3%
0.00017
Низкий

5.3 Medium

CVSS4

Дефекты

CWE-295