CVE-2024-2431

GlobalProtect App: Local User Can Disable GlobalProtect

Severity
Medium 5.5
CVSS 3.1
Exploited
Not listed
EPSS
0.002
5.0th percentile
Discovered by
Third party
Published by the vendor
Published
Mar 13, 2024
Assigned by palo_alto

Description

An issue in the Palo Alto Networks GlobalProtect app enables a non-privileged user to disable the GlobalProtect app in configurations that allow a user to disable GlobalProtect with a passcode.

Weakness: CWE-269

Affected products

Vendor Product Category Matched by
Palo Alto Networks GlobalProtect VPN & Remote Access cna-assigner
Vendor-reported affected versions (2)
  • Palo Alto Networks · GlobalProtect App
  • paloaltonetworks · globalprotect

Credit

Palo Alto Networks thanks AIG Red Team and Stephen Collyer for discovering and reporting this issue.

Vendor remediation

This issue is fixed in GlobalProtect app 5.1.12, GlobalProtect app 5.2.13, GlobalProtect app 6.0.4, GlobalProtect app 6.1.1, and all later GlobalProtect app versions.