CVE-2012-6606Medium
CVE-2012-6606 Man-in-the-middle Vulnerability in GlobalProtect App
🔗 CVE IDs covered (1)
📋 Description
A vulnerability exists in NetConnect (all version) and GlobalPortect App (1.1.6 and earlier) whereby the agent does not verify the certificate presented by the portal server, enabling a possible Man-in-the-middle attack. This vulnerability can result in an agent connecting to an attacker-controlled server allowing the attacker to receive the username and password of the affected user. This issue affects NetConnect (all versions); GlobalProtect App (1.1.6 and earlier).
🎯 Affected products2
- GlobalProtect App
- NetConnect
✅ Remediation
GlobalProtect app 1.1.7 and later; NetConnect is discontinued. Workarounds and mitigations: No mitigations available.