GlobalProtect App: Missing certificate validation vulnerability can disclose pre-logon authentication cookie
Published Jun 10, 2020
5.3
MEDIUMCVSS 3.1
EPSS 0.87%
Description
When the pre-logon feature is enabled, a missing certification validation in Palo Alto Networks GlobalProtect app can disclose the pre-logon authentication cookie to a man-in-the-middle attacker on the same local area network segment with the ability to manipulate ARP or to conduct ARP spoofing attacks. This allows the attacker to access the GlobalProtect Server as allowed by configured Security rules for the 'pre-login' user. This access may be limited compared to the network access of regular users. This issue affects: GlobalProtect app 5.0 versions earlier than GlobalProtect app 5.0.10 when the prelogon feature is enabled; GlobalProtect app 5.1 versions earlier than GlobalProtect app 5.1.4 when the prelogon feature is enabled.
Affected products
-
- Version 5.0StatusaffectedConstraints<5.0.10
- Version 5.1StatusaffectedConstraints<5.1.4
- Version
Default status is the baseline for the product, each version can override it (e.g. patched versions marked unaffected).
| Vendor | Product | Default status | Versions | |||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|
| Palo Alto Networks | GlobalProtect App | n/a |
|
- ≥ 5.0.0 · < 5.0.10
- ≥ 5.1.0 · < 5.1.4
No data.
No Red Hat product state for this CVE.
No package ranges for this CVE.
Remediation
Vendor solution
This issue is fixed in GlobalProtect app 5.0.10, GlobalProtect app 5.1.4, and all later GlobalProtect app versions.
References (1)
- https://security.paloaltonetworks.com/CVE-2020-2033 x_refsource_MISCVendor Advisory
| Link | Providers | Tags |
|---|---|---|
| https://security.paloaltonetworks.com/CVE-2020-2033 | x_refsource_MISCVendor Advisory |
Change history (0)
No recorded changes yet.