An information exposure vulnerability exists in Palo Alto Networks PAN-OS software that enables a GlobalProtect end user to learn both the configured GlobalProtect uninstall password and the configured disable or disconnect passcode. After the password or passcode is known, end users can uninstall, disable, or disconnect GlobalProtect even if the GlobalProtect app configuration would not normally permit them to do so.
References
Link | Resource |
---|---|
https://security.paloaltonetworks.com/CVE-2024-8687 | Vendor Advisory |
Configurations
Configuration 1 (hide)
|
Configuration 2 (hide)
|
Configuration 3 (hide)
AND |
|
History
03 Oct 2024, 00:26
Type | Values Removed | Values Added |
---|---|---|
CWE | NVD-CWE-noinfo | |
CVSS |
v2 : v3 : |
v2 : unknown
v3 : 7.1 |
First Time |
Paloaltonetworks globalprotect
Paloaltonetworks prisma Access Paloaltonetworks pan-os Paloaltonetworks |
|
CPE | cpe:2.3:o:paloaltonetworks:pan-os:11.0.0:*:*:*:*:*:*:* cpe:2.3:a:paloaltonetworks:globalprotect:*:*:*:*:*:*:*:* cpe:2.3:o:paloaltonetworks:pan-os:*:*:*:*:*:*:*:* cpe:2.3:a:paloaltonetworks:globalprotect:6.2.0:*:*:*:*:*:*:* cpe:2.3:a:paloaltonetworks:prisma_access:-:*:*:*:*:*:*:* |
|
References | () https://security.paloaltonetworks.com/CVE-2024-8687 - Vendor Advisory |
12 Sep 2024, 12:35
Type | Values Removed | Values Added |
---|---|---|
Summary |
|
11 Sep 2024, 17:15
Type | Values Removed | Values Added |
---|---|---|
New CVE |
Information
Published : 2024-09-11 17:15
Updated : 2024-10-03 00:26
NVD link : CVE-2024-8687
Mitre link : CVE-2024-8687
CVE.ORG link : CVE-2024-8687
JSON object : View
Products Affected
paloaltonetworks
- prisma_access
- globalprotect
- pan-os
CWE