CVE-2024-2431: GlobalProtect App: Local User Can Disable GlobalProtect
Published Mar 13, 2024
·Updated
An issue in the Palo Alto Networks GlobalProtect app enables a non-privileged user to disable the GlobalProtect app in configurations that allow a user to disable GlobalProtect with a passcode.
Affected Software
5 affected components
Palo Alto Networks GlobalProtect
Palo Alto Networks GlobalProtect>=5.1.0<5.1.12
Palo Alto Networks GlobalProtect>=5.2.0<=5.2.13
Palo Alto Networks GlobalProtect>=6.0.0<6.0.4
Palo Alto Networks GlobalProtect=6.1.0
Remediation
Information
This issue is fixed in GlobalProtect app 5.1.12, GlobalProtect app 5.2.13, GlobalProtect app 6.0.4, GlobalProtect app 6.1.1, and all later GlobalProtect app versions.
Event History
Mar 13, 2024
CVE Published
via MITRE·05:51 PM
Data Sourced
via MITRE·05:51 PM
RemedyDescriptionSeverityWeakness
Data Sourced
via NVD·06:15 PM
DescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2024-2431?
CVE-2024-2431 is categorized as a medium severity vulnerability.
2
How do I fix CVE-2024-2431?
To fix CVE-2024-2431, ensure that the GlobalProtect app configuration does not allow non-privileged users to disable the application with a passcode.
3
What systems are affected by CVE-2024-2431?
CVE-2024-2431 affects the Palo Alto Networks GlobalProtect application.
4
Can CVE-2024-2431 be exploited remotely?
CVE-2024-2431 can be exploited locally by a non-privileged user with access to the GlobalProtect app.
5
What mitigation strategies exist for CVE-2024-2431?
Mitigation for CVE-2024-2431 includes restricting configurations that allow users to disable the GlobalProtect app.