Description
GlobalProtect Agent 4.1.0 for Windows and GlobalProtect Agent 4.1.10 and earlier for macOS may allow a local authenticated attacker who has compromised the end-user account and gained the ability to inspect memory, to access authentication and/or session tokens and replay them to spoof the VPN session and gain access as the user.
CVSS breakdown
CVSS 3.1
Attack Vector
Local
Attack Complexity
High
Privileges Required
Low
User Interaction
None
Scope
Unchanged
Confidentiality
Low
Integrity
None
Availability
None
Affected products
- Palo Alto Networks / GlobalProtect Agent4.1 – 4.1.0
- Palo Alto Networks / GlobalProtect Agent4.1.11 – 4.1*
References
- MISChttps://www.kb.cert.org/vuls/id/192371
- MISChttp://www.securityfocus.com/bid/107868
- VENDOR_ADVISORYhttps://psirt.global.sonicwall.com/vuln-detail/SNWLID-2019-0005
- VENDOR_ADVISORYhttps://www.broadcom.com/support/fibre-channel-networking/security-advisories/brocade-security-advisory-2019-783
- MISChttps://security.paloaltonetworks.com/CVE-2019-1573