CVE-2024-3388 PAN-OS: User Impersonation in GlobalProtect SSL VPN
🔗 CVE IDs covered (1)
📋 Description
A vulnerability in the GlobalProtect Gateway in Palo Alto Networks PAN-OS software enables an authenticated attacker to impersonate another user and send network packets to internal assets. However, this vulnerability does not allow the attacker to receive response packets from those internal assets.
🎯 Affected products3
- PAN-OS
- Cloud NGFW
- Prisma Access
✅ Remediation
This issue is fixed in PAN-OS 8.1.26, PAN-OS 9.0.17-h4, PAN-OS 9.1.17, PAN-OS 10.1.11-h4, PAN-OS 10.2.7-h3, PAN-OS 11.0.3, and all later PAN-OS versions. This issue is fixed in Prisma Access 10.2.4 and later. Workarounds and mitigations: You can enable the "Disable Automatic Restoration of SSL VPN" (Network > GlobalProtect Gateways > > GlobalProtect Gateway Configuration > Agent > Connection Settings) on PAN-OS firewalls with the GlobalProtect feature enabled to mitigate this vulnerability.