CVE-2019-1573: Information Disclosure in GlobalProtect Agent
GlobalProtect Agent 4.1.0 for Windows and GlobalProtect Agent 4.1.10 and earlier for macOS may allow a local authenticated attacker who has compromised the end-user account and gained the ability to inspect memory, to access authentication and/or session tokens and replay them to spoof the VPN session and gain access as the user.
Affected Software
Remediation
Information
Event History
Frequently Asked Questions
What is CVE-2019-1573?
CVE-2019-1573 is a vulnerability in GlobalProtect Agent 4.1.0 for Windows and GlobalProtect Agent 4.1.10 and earlier for macOS that allows a local authenticated attacker to access authentication and/or session tokens.
What is the severity of CVE-2019-1573?
CVE-2019-1573 has a severity rating of low (2.5).
How does CVE-2019-1573 work?
CVE-2019-1573 allows a local authenticated attacker who has compromised the end-user account to inspect memory and access authentication/session tokens, which can be replayed to spoof the VPN session.
Is there a fix for CVE-2019-1573?
Yes, PaloAlto Networks has released updates to address this vulnerability. Please refer to their official website for the latest patches.
Are there any references for CVE-2019-1573?
Yes, you can find more information about CVE-2019-1573 at the following references: [1] http://www.securityfocus.com/bid/107868, [2] https://psirt.global.sonicwall.com/vuln-detail/SNWLID-2019-0005, [3] https://security.paloaltonetworks.com/CVE-2019-1573