Aller au contenu

Fiche vulnérabilité

CVE-2024-8687 : faille élevée paloaltonetworks pan-os (CVSS 7.1)

Description

An information exposure vulnerability exists in Palo Alto Networks PAN-OS software that enables a GlobalProtect end user to learn both the configured GlobalProtect uninstall password and the configured disable or disconnect passcode. After the password or passcode is known, end users can uninstall, disable, or disconnect GlobalProtect even if the GlobalProtect app configuration would not normally permit them to do so.

En bref

Sévérité
Élevée (CVSS 7.1)
Vecteur CVSS
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:H
Exploitation active
Non signalée par la CISA
Publication
11 sept. 2024
Dernière mise à jour
17 juin 2026

Produits concernés

  • paloaltonetworks pan-os
  • paloaltonetworks globalprotect
  • paloaltonetworks prisma access

Références

Rechercher une autre vulnérabilité dans la base CVE