CVE-2024-5918: PAN-OS: Improper Certificate Validation Enables Impersonation of a Legitimate GlobalProtect User (Severity: LOW)
An improper certificate validation vulnerability in Palo Alto Networks PAN-OS software enables an authorized user with a specially crafted client certificate to connect to an impacted GlobalProtect portal or GlobalProtect gateway as a different legitimate user. This attack is possible only if you "Allow Authentication with User Credentials OR Client Certificate."
Affected Software
Remediation
Mitigation
Information
Event History
Frequently Asked Questions
What is the severity of CVE-2024-5918?
CVE-2024-5918 is classified as a high severity vulnerability due to its potential impact on user authentication.
How do I fix CVE-2024-5918?
To fix CVE-2024-5918, update your PAN-OS software to version 11.0.4 or later, 10.2.5-h5, or 10.1.12.
What systems are affected by CVE-2024-5918?
CVE-2024-5918 affects Palo Alto Networks PAN-OS, Cloud NGFW, and Prisma Access if running specified vulnerable versions.
What is the impact of exploiting CVE-2024-5918?
Exploitation of CVE-2024-5918 allows an unauthorized user to impersonate legitimate users by using a specially crafted client certificate.
Who should be concerned about CVE-2024-5918?
Organizations using affected Palo Alto Networks products should prioritize addressing CVE-2024-5918 to protect user authentication integrity.