CVE-2012-6606Medium

CVE-2012-6606 Man-in-the-middle Vulnerability in GlobalProtect App

Published
October 22, 2012
Last Modified
October 22, 2012

🔗 CVE IDs covered (1)

📋 Description

A vulnerability exists in NetConnect (all version) and GlobalPortect App (1.1.6 and earlier) whereby the agent does not verify the certificate presented by the portal server, enabling a possible Man-in-the-middle attack. This vulnerability can result in an agent connecting to an attacker-controlled server allowing the attacker to receive the username and password of the affected user. This issue affects NetConnect (all versions); GlobalProtect App (1.1.6 and earlier).

🎯 Affected products2

  • GlobalProtect App
  • NetConnect

✅ Remediation

GlobalProtect app 1.1.7 and later; NetConnect is discontinued. Workarounds and mitigations: No mitigations available.

🔗 References (1)