Authentication bypass vulnerabilities in the GlobalProtect portal and gateway of Palo Alto Networks PAN-OS® software allows the attacker to bypass security restrictions and establish an unauthorized VPN connection. Panorama and Cloud NGFW are not impacted by these issues.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
< 10.2.7CPE matchmatch criteria | cpe:2.3:o:paloaltonetworks:pan-os:*:*:*:*:*:*:*:* | ||
10.2.7CPE matchmatch criteria | cpe:2.3:o:paloaltonetworks:pan-os:10.2.7:-:*:*:*:*:*:* | ||
10.2.7CPE matchmatch criteria | cpe:2.3:o:paloaltonetworks:pan-os:10.2.7:h1:*:*:*:*:*:* | ||
10.2.7CPE matchmatch criteria | cpe:2.3:o:paloaltonetworks:pan-os:10.2.7:h12:*:*:*:*:*:* | ||
10.2.7CPE matchmatch criteria | cpe:2.3:o:paloaltonetworks:pan-os:10.2.7:h16:*:*:*:*:*:* |
CVSS version used by this source: 4.0
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:N/VA:N/SC:H/SI:H/SA:N/E:A/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:N/R:A/V:D/RE:M/U:Red
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.3 Bluesky, 0.3 Mastodon, and 2.4 GitHub mentions.
The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.