imPC@ndo IT

Tracker / CVE-2024-8687

CVE-2024-8687

High 7.1

An information exposure vulnerability exists in Palo Alto Networks PAN-OS software that enables a GlobalProtect end user to learn both the configured GlobalProtect uninstall password and the configured disable or disconnect passcode. After the password or passcode is known, end users can uninstall, disable, or disconnect GlobalProtect even if the GlobalProtect app configuration would not normally permit them to do so.

Affected products and versions

paloaltonetworks globalprotect
paloaltonetworks globalprotect · 5.1.0 → 5.1.12
paloaltonetworks globalprotect · 5.2.0 → 5.2.13
paloaltonetworks globalprotect · 6.0.0 → 6.0.7
paloaltonetworks globalprotect · 6.1.0 → 6.1.2
paloaltonetworks pan-os
paloaltonetworks pan-os · 10.0.0 → 10.0.12
paloaltonetworks pan-os · 10.1.0 → 10.1.9
paloaltonetworks pan-os · 10.2.0 → 10.2.4
paloaltonetworks pan-os · 8.1.0 → 8.1.25
paloaltonetworks pan-os · 9.0.0 → 9.0.17
paloaltonetworks pan-os · 9.1.0 → 9.1.16
paloaltonetworks prisma_access

Analysis

This page is not indexable yet.Until it carries original analysis — what it actually exposes, how to check in two minutes whether a system was touched, what to do if it was — the page stays noindex. The database decides that, not the template.

References