Palo Alto Security Updates – 14 March 2024

Palo Alto has released security updates to address multiple vulnerabilities affecting GlobalProtect App and PAN-OS.

The addressed vulnerabilities could allow the attacker to gain elevated privileges to the affected products.

Sample of the addressed vulnerabilities:

GlobalProtect App: Local User Can Disable GlobalProtect (CVE-2024-2431):

  • CVSS: 5.7
  • Attack Vector: Local
  • Attack Complexity: Low
  • Privileges Required: Low
  • User Interaction: None
  • Consequences: Gain Privileges

Sample of the affected products:

  • PAN-OS 11.0 < 11.0.3 on Panorama.
  • PAN-OS 10.2 < 10.2.8 on Panorama.
  • PAN-OS 9.1 < 9.1.17 on Panorama.
  • GlobalProtect App 6.2 < 6.2.1 on Windows.
  • GlobalProtect App 6.1 < 6.1.2 on Windows.
Vulnerabilities
  • CVE-2024-2431
  • CVE-2024-2432
  • CVE-2024-2433
Mitigations

The enterprise should deploy this patch as soon as the testing phase is completed.

Palo Alto Security Advisory

References