Palo Alto Networks Vulnerabilities and Affected Products
Vulnerabilities associated with Global Protect Agent.
Products
Clear product- PAN-OS189 vulnerabilities
- Prisma Access112 vulnerabilities
- Cloud NGFW104 vulnerabilities
- GlobalProtect App38 vulnerabilities
- Cortex XDR Agent24 vulnerabilities
- Expedition12 vulnerabilities
- Prisma Access Agent12 vulnerabilities
- Cortex XSOAR11 vulnerabilities
- GlobalProtect UWP App9 vulnerabilities
- Prisma Browser9 vulnerabilities
- Cortex XDR Broker VM8 vulnerabilities
- Panorama7 vulnerabilities
- Prisma Cloud Compute4 vulnerabilities
- Global Protect Agent3 vulnerabilities
- Trust Protection Foundation3 vulnerabilities
- Autonomous Digital Experience Manager2 vulnerabilities
- Bridgecrew Checkov2 vulnerabilities
- Checkov by Prisma Cloud2 vulnerabilities
- Palo Alto Networks Expedition2 vulnerabilities
- Palo Alto Networks PAN-OS2 vulnerabilities
- Prisma Access Browser2 vulnerabilities
- Prisma SD-WAN ION2 vulnerabilities
- Traps2 vulnerabilities
- ActiveMQ Content Pack1 vulnerability
- Broker VM1 vulnerability
| Vulnerability | Title and context | CVSS | EPSS | PoCs | Signals | STIX action |
|---|---|---|---|---|---|---|
CVE-2020-1989HIGH | Global Protect Agent: Incorrect privilege assignment allows local privilege escalationAn incorrect privilege assignment vulnerability when writing application-specific files in the Palo Alto Networks Global Protect Agent for Linux on ARM platform allows a local authenticated user to gain root privileges on the system. This issue affects Palo Alto Networks Global Protect Agent for Linux 5.0 versions before 5.0.8; 5.1 versions before 5.1.1. | CVSS7.0v3.1 | EPSS0.265% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2020-1988MEDIUM | Global Protect Agent: Local privilege escalation due to an unquoted search path vulnerabilityAn unquoted search path vulnerability in the Windows release of Global Protect Agent allows an authenticated local user with file creation privileges on the root of the OS disk (C:\) or to Program Files directory to gain system privileges. This issue affects Palo Alto Networks GlobalProtect Agent 5.0 versions before 5.0.5; 4.1 versions before 4.1.13 on Windows; CWE-428Apr 8, 2020 | CVSS4.2v3.1 | EPSS0.37% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
Global Protect Agent: VPN cookie local information disclosureAn information exposure vulnerability in the logging component of Palo Alto Networks Global Protect Agent allows a local authenticated user to read VPN cookie information when the troubleshooting logging level is set to "Dump". This issue affects Palo Alto Networks Global Protect Agent 5.0 versions prior to 5.0.9; 5.1 versions prior to 5.1.1. | CVSS3.9v3.1 | EPSS0.301% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |