PAN-OS: User Impersonation in GlobalProtect Portal
Vulnerability Description
A vulnerability in the GlobalProtect portal in Palo Alto Networks PAN-OS software enables a malicious authenticated GlobalProtect user to impersonate another GlobalProtect user. Active GlobalProtect users impersonated by an attacker who is exploiting this vulnerability are disconnected from GlobalProtect. Upon exploitation, PAN-OS logs indicate that the impersonated user authenticated to GlobalProtect, which hides the identity of the attacker.
Impact Analysis
Refer to official advisory for detailed impact metrics.
Remediation
Ensure systems are updated to the latest vendor-supplied patch levels.
Am I Vulnerable?
Launch our assessment wizard to check if your infrastructure is exposed to • CVE-2024-8691
Credits & Attribution
The following person or organization is credited with identifying this vulnerability, as recorded in the NVD database:
- Claudiu Pancotan
More from Palo Alto Networks
View All →Affected Vendor
Palo Alto Networks
View all reports →