CVE-2020-1976: GlobalProtect on MacOS: Local denial-of-service (DoS) vulnerability.
A denial-of-service (DoS) vulnerability in Palo Alto Networks GlobalProtect software running on Mac OS allows authenticated local users to cause the Mac OS kernel to hang or crash. This issue affects GlobalProtect 5.0.5 and earlier versions of GlobalProtect 5.0 on Mac OS.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
Palo Alto Networks GlobalProtect (Mac OS)to a version that resolves this vulnerability.Fixed in 5.0.6 - Upgrade
Upgrade
Palo Alto Networks GlobalProtect (Mac OS)to a version that resolves this vulnerability.Fixed in 5.1.0
Event History
Frequently Asked Questions
What is CVE-2020-1976?
CVE-2020-1976 is a denial-of-service (DoS) vulnerability in Palo Alto Networks GlobalProtect software running on Mac OS.
Who is affected by CVE-2020-1976?
Authenticated local users running Palo Alto Networks GlobalProtect 5.0.5 and earlier versions on Mac OS are affected by CVE-2020-1976.
How can an attacker exploit CVE-2020-1976?
An attacker can exploit CVE-2020-1976 by causing the Mac OS kernel to hang or crash, resulting in a Denial-of-Service (DoS) condition.
What is the severity of CVE-2020-1976?
CVE-2020-1976 has a severity rating of medium with a CVSS score of 5.5.
How can I mitigate CVE-2020-1976?
To mitigate CVE-2020-1976, it is recommended to update to GlobalProtect version 5.0.6 or later.