CVE-2024-3388

A vulnerability in the GlobalProtect Gateway in Palo Alto Networks PAN-OS software enables an authenticated attacker to impersonate another user and send network packets to internal assets. However, this vulnerability does not allow the attacker to receive response packets from those internal assets.
Configurations

No configuration.

History

21 Nov 2024, 09:29

Type Values Removed Values Added
References () https://security.paloaltonetworks.com/CVE-2024-3388 - () https://security.paloaltonetworks.com/CVE-2024-3388 -
Summary
  • (es) Una vulnerabilidad en GlobalProtect Gateway del software PAN-OS de Palo Alto Networks permite que un atacante autenticado se haga pasar por otro usuario y envíe paquetes de red a recursos internos. Sin embargo, esta vulnerabilidad no permite que el atacante reciba paquetes de respuesta de esos recursos internos.

10 Apr 2024, 17:15

Type Values Removed Values Added
New CVE

Information

Published : 2024-04-10 17:15

Updated : 2024-11-21 09:29


NVD link : CVE-2024-3388

Mitre link : CVE-2024-3388

CVE.ORG link : CVE-2024-3388


JSON object : View

Products Affected

No product.

CWE
CWE-269

Improper Privilege Management

CWE-863

Incorrect Authorization