Vulnerability Fixed in Palo Alto Networks PAN-OS and Prisma Access (advisories.ncsc.nl)
0xBASE INTEL BRIEF
- Palo Alto Networks fixes critical GlobalProtect vulnerability
- Attackers can establish VPN connection without authentication
- Active exploitation and public proof-of-concept code
"Palo Alto Networks has fixed a vulnerability in GlobalProtect portal and gateway components of PAN-OS. An unauthenticated attacker can exploit it to establish a VPN connection, gaining access to internal systems. Active exploitation reported by Rapid7; proof-of-concept code is public. The Dutch NCSC expects increased exploitation scale."
#Palo-Alto-vulnerability
#GlobalProtect-flaw
#active-exploitation
no comments yet.