CVE-2024-5921
GlobalProtect App: Insufficient Certificate Validation Leads to Privilege Escalation
Severity Score
Exploit Likelihood
Affected Versions
Public Exploits
2Exploited in Wild
-Decision
Descriptions
An insufficient certification validation issue in the Palo Alto Networks GlobalProtect app enables attackers to connect the GlobalProtect app to arbitrary servers. This can enable a local non-administrative operating system user or an attacker on the same subnet to install malicious root certificates on the endpoint and subsequently install malicious software signed by the malicious root certificates on that endpoint. GlobalProtect App for Android is under evaluation. Please subscribe to our RSS feed https://security.paloaltonetworks.com/rss.xml to be alerted to new updates to this and other advisories.
An insufficient certification validation issue in the Palo Alto Networks GlobalProtect app enables attackers to connect the GlobalProtect app to arbitrary servers. This can enable a local non-administrative operating system user or an attacker on the same subnet to install malicious root certificates on the endpoint and subsequently install malicious software signed by the malicious root certificates on that endpoint. Please subscribe to our RSS feed https://security.paloaltonetworks.com/rss.xml to be alerted to new updates to this and other advisories.
CVSS Scores
SSVC
- Decision:Attend
Timeline
- 2024-06-12 CVE Reserved
- 2024-11-27 CVE Published
- 2025-02-20 CVE Updated
- 2025-02-20 First Exploit
- 2025-05-07 EPSS Updated
- ---------- Exploited in Wild
- ---------- KEV Due Date
CWE
- CWE-295: Improper Certificate Validation
CAPEC
- CAPEC-233: Privilege Escalation
References (3)
URL | Tag | Source |
---|
URL | Date | SRC |
---|
URL | Date | SRC |
---|---|---|
https://security.paloaltonetworks.com/CVE-2024-5921 | 2024-11-27 |
Affected Vendors, Products, and Versions
Vendor | Product | Version | Other | Status | ||||||
---|---|---|---|---|---|---|---|---|---|---|
Vendor | Product | Version | Other | Status | <-- --> | Vendor | Product | Version | Other | Status |
Palo Alto Networks Search vendor "Palo Alto Networks" | GlobalProtect App Search vendor "Palo Alto Networks" for product "GlobalProtect App" | >= 6.3.0 < 6.3.2 Search vendor "Palo Alto Networks" for product "GlobalProtect App" and version " >= 6.3.0 < 6.3.2" | en |
Affected
| ||||||
Palo Alto Networks Search vendor "Palo Alto Networks" | GlobalProtect App Search vendor "Palo Alto Networks" for product "GlobalProtect App" | >= 6.2.0 < 6.2.6 Search vendor "Palo Alto Networks" for product "GlobalProtect App" and version " >= 6.2.0 < 6.2.6" | en |
Affected
| ||||||
Palo Alto Networks Search vendor "Palo Alto Networks" | GlobalProtect App Search vendor "Palo Alto Networks" for product "GlobalProtect App" | >= 6.3.0 < 6.3.2 Search vendor "Palo Alto Networks" for product "GlobalProtect App" and version " >= 6.3.0 < 6.3.2" | en |
Affected
| ||||||
Palo Alto Networks Search vendor "Palo Alto Networks" | GlobalProtect App Search vendor "Palo Alto Networks" for product "GlobalProtect App" | >= 6.1.0 < 6.1.6 Search vendor "Palo Alto Networks" for product "GlobalProtect App" and version " >= 6.1.0 < 6.1.6" | en |
Affected
| ||||||
Palo Alto Networks Search vendor "Palo Alto Networks" | GlobalProtect App Search vendor "Palo Alto Networks" for product "GlobalProtect App" | >= 6.1.0 < 6.1.7 Search vendor "Palo Alto Networks" for product "GlobalProtect App" and version " >= 6.1.0 < 6.1.7" | en |
Affected
| ||||||
Palo Alto Networks Search vendor "Palo Alto Networks" | GlobalProtect App Search vendor "Palo Alto Networks" for product "GlobalProtect App" | >= 6.2.0 < 6.2.6 Search vendor "Palo Alto Networks" for product "GlobalProtect App" and version " >= 6.2.0 < 6.2.6" | en |
Affected
|