CVE-2019-1573 describes a vulnerability in GlobalProtect Agent 4.1.0 for Windows and 4.1.10 and earlier for macOS, where a local, authenticated attacker can access authentication and/or session tokens by inspecting memory. This allows them to replay tokens, spoofing a VPN session and gaining unauthorized access as the legitimate user. The vulnerability has a low CVSS score of 2.5, indicating a local attack vector with high attack complexity and limited impact on confidentiality. There is no evidence of active exploitation, public exploit code, or inclusion in the KEV catalog, though it has garnered some community discussion and media coverage.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
<= 4.1.0CPE matchmatch criteria | cpe:2.3:a:paloaltonetworks:globalprotect:*:*:*:*:*:windows:*:* | ||
<= 4.1.10CPE matchmatch criteria | cpe:2.3:a:paloaltonetworks:globalprotect:*:*:*:*:*:macos:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:L/I:N/A:N
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.0 Mastodon, and 0.2 GitHub mentions.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.