imPC@ndo IT

Tracker / CVE-2020-1989

CVE-2020-1989

High 7.0

An incorrect privilege assignment vulnerability when writing application-specific files in the Palo Alto Networks Global Protect Agent for Linux on ARM platform allows a local authenticated user to gain root privileges on the system. This issue affects Palo Alto Networks Global Protect Agent for Linux 5.0 versions before 5.0.8; 5.1 versions before 5.1.1.

Affected products and versions

paloaltonetworks globalprotect · 5.0 → 5.0.8
paloaltonetworks globalprotect · 5.1 → 5.1.1

Analysis

This page is not indexable yet.Until it carries original analysis — what it actually exposes, how to check in two minutes whether a system was touched, what to do if it was — the page stays noindex. The database decides that, not the template.

References