Palo Alto Networks GlobalProtect是美国Palo Alto Networks公司的一套网络防护软件。该软件可提供防火墙监控及威胁预防等功能。 Palo Alto Networks GlobalProtect 存在安全漏洞,使得通过身份验证访问GlobalProtect portal and gateway的攻击者能够连接到托管在Amazon AWS上的VM系列防火墙的EC2实例元数据端点。攻击者可利用该漏洞执行AWS中EC2角色允许的任何操作。受影响的系统包括:PAN-OS
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| Palo Alto Networks | PAN-OS | 10.1.* | - |
|
| Palo Alto Networks | Prisma Access | 2.1 all | - |
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2021-3064 | 9.8 CRITICAL | PAN-OS: Memory Corruption Vulnerability in GlobalProtect Portal and Gateway Interfaces |
| CVE-2021-3058 | 8.8 HIGH | PAN-OS: OS Command Injection Vulnerability in Web Interface XML API |
| CVE-2021-3056 | 8.8 HIGH | PAN-OS: Memory Corruption Vulnerability in GlobalProtect Clientless VPN During SAML Authen |
| CVE-2021-3060 | 8.1 HIGH | PAN-OS: OS Command Injection in Simple Certificate Enrollment Protocol (SCEP) |
| CVE-2021-3059 | 8.1 HIGH | PAN-OS: OS Command Injection Vulnerability When Performing Dynamic Updates |
| CVE-2021-3063 | 7.5 HIGH | PAN-OS: Denial-of-Service (DoS) Vulnerability in GlobalProtect Portal and Gateway Interfac |
| CVE-2021-3061 | 6.4 MEDIUM | PAN-OS: OS Command Injection Vulnerability in the Command Line Interface (CLI) |
No comments yet