CVE-2024-3383: PAN-OS: Improper Group Membership Change Vulnerability in Cloud Identity Engine (CIE)
A vulnerability in how Palo Alto Networks PAN-OS software processes data received from Cloud Identity Engine (CIE) agents enables modification of User-ID groups. This impacts user access to network resources where users may be inappropriately denied or allowed access to resources based on your existing Security Policy rules.
Affected Software
Remediation
Information
Event History
Frequently Asked Questions
What is the severity of CVE-2024-3383?
CVE-2024-3383 has been rated with a severity level that indicates a significant risk to user access management in affected versions of PAN-OS.
How do I fix CVE-2024-3383?
To resolve CVE-2024-3383, upgrade your Palo Alto Networks PAN-OS software to a version above 10.1.11, 10.2.5, or 11.0.3.
What versions of PAN-OS are affected by CVE-2024-3383?
CVE-2024-3383 affects Palo Alto Networks PAN-OS versions from 10.1.0 to 10.1.11, 10.2.0 to 10.2.5, and 11.0.0 to 11.0.3.
What impact does CVE-2024-3383 have on network resources?
CVE-2024-3383 can lead to improper modification of User-ID groups, which may cause users to be incorrectly granted or denied access to network resources.
Is CVE-2024-3383 being actively exploited?
At the moment, there are no known active exploitations reported for CVE-2024-3383, but it is important to apply the necessary updates to mitigate potential risks.