Palo Alto Networks GlobalProtect是美国Palo Alto Networks公司的一套网络防护软件。该软件可提供防火墙监控及威胁预防等功能。 Palo Alto Networks GlobalProtect应用程序在Windows上存在后置链接漏洞,本地攻击者可利用该漏洞能够破坏系统进程,并可能在某些情况下使用系统特权执行任意代码。以下产品及版本受到影响:Windows下GlobalProtect app 5.1.10之前的5.1.x版本,GlobalProtect app
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| Palo Alto Networks | GlobalProtect App | 5.2 ~ 5.2.5 | - |
|
| Palo Alto Networks | GlobalProtect App | 5.3.* | - |
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2022-0016 | 7.4 HIGH | GlobalProtect App: Privilege Escalation Vulnerability When Using Connect Before Logon |
| CVE-2022-0020 | 6.8 MEDIUM | Cortex XSOAR: Stored Cross-Site Scripting (XSS) Vulnerability in Web Interface |
| CVE-2022-0011 | 6.5 MEDIUM | PAN-OS: URL Category Exceptions Match More URLs Than Intended in URL Filtering |
| CVE-2022-0018 | 6.1 MEDIUM | GlobalProtect App: Information Exposure Vulnerability When Connecting to GlobalProtect Por |
| CVE-2022-0019 | 4.7 MEDIUM | GlobalProtect App: Insufficiently Protected Credentials Vulnerability on Linux |
| CVE-2022-0021 | 3.3 LOW | GlobalProtect App: Information Exposure Vulnerability When Using Connect Before Logon |
No comments yet