PAN-OS: Improper Certificate Validation Enables Impersonation of a Legitimate GlobalProtect User
Vulnerability Description
An improper certificate validation vulnerability in Palo Alto Networks PAN-OS software enables an authorized user with a specially crafted client certificate to connect to an impacted GlobalProtect portal or GlobalProtect gateway as a different legitimate user. This attack is possible only if you "Allow Authentication with User Credentials OR Client Certificate."
Impact Analysis
Refer to official advisory for detailed impact metrics.
Remediation
Ensure systems are updated to the latest vendor-supplied patch levels.
Am I Vulnerable?
Launch our assessment wizard to check if your infrastructure is exposed to • CVE-2024-5918
Credits & Attribution
No credits recorded in the NVD database.
More from Palo Alto Networks
View All →Affected Vendor
Palo Alto Networks
View all reports →