First published: Wed Mar 13 2024(Updated: )
An issue in the Palo Alto Networks GlobalProtect app enables a non-privileged user to disable the GlobalProtect app in configurations that allow a user to disable GlobalProtect with a passcode.
Credit: psirt@paloaltonetworks.com
Affected Software | Affected Version | How to fix |
---|---|---|
Palo Alto Networks GlobalProtect UWP App |
This issue is fixed in GlobalProtect app 5.1.12, GlobalProtect app 5.2.13, GlobalProtect app 6.0.4, GlobalProtect app 6.1.1, and all later GlobalProtect app versions.
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2024-2431 is categorized as a medium severity vulnerability.
To fix CVE-2024-2431, ensure that the GlobalProtect app configuration does not allow non-privileged users to disable the application with a passcode.
CVE-2024-2431 affects the Palo Alto Networks GlobalProtect application.
CVE-2024-2431 can be exploited locally by a non-privileged user with access to the GlobalProtect app.
Mitigation for CVE-2024-2431 includes restricting configurations that allow users to disable the GlobalProtect app.