CVE-2024-3388Medium

CVE-2024-3388 PAN-OS: User Impersonation in GlobalProtect SSL VPN

Published
April 10, 2024
Last Modified
April 10, 2024

🔗 CVE IDs covered (1)

📋 Description

A vulnerability in the GlobalProtect Gateway in Palo Alto Networks PAN-OS software enables an authenticated attacker to impersonate another user and send network packets to internal assets. However, this vulnerability does not allow the attacker to receive response packets from those internal assets.

🎯 Affected products3

  • PAN-OS
  • Cloud NGFW
  • Prisma Access

✅ Remediation

This issue is fixed in PAN-OS 8.1.26, PAN-OS 9.0.17-h4, PAN-OS 9.1.17, PAN-OS 10.1.11-h4, PAN-OS 10.2.7-h3, PAN-OS 11.0.3, and all later PAN-OS versions. This issue is fixed in Prisma Access 10.2.4 and later. Workarounds and mitigations: You can enable the "Disable Automatic Restoration of SSL VPN" (Network > GlobalProtect Gateways > > GlobalProtect Gateway Configuration > Agent > Connection Settings) on PAN-OS firewalls with the GlobalProtect feature enabled to mitigate this vulnerability.

🔗 References (1)