Palo Alto Networks (GlobalProtect App,PAN-OS,Cloud NGFW,Prisma Access) Family of Products March 2024 Security Update Advisory

Overview

 

Palo Alto Networks(https://www.paloaltonetworks.com/) has released a security update that fixes vulnerabilities in products it has been made. users of affected products are advised to update to the latest version.

 

Affected Products

 

GlobalProtect App prior to version 6.1.1

GlobalProtect App prior to version 6.0.4

GlobalProtect App prior to version 5.2.13

GlobalProtect App prior to version 5.1.12

GlobalProtect App prior to version 6.2.1

GlobalProtect App prior to version 6.1.2

GlobalProtect App prior to version 6.0.8

GlobalProtect App prior to version 5.1.12

PAN-OS,Cloud NGFW,Prisma Access prior to version 11.0.3

PAN-OS,Cloud NGFW,Prisma Access prior to version 10.2.8

PAN-OS,Cloud NGFW,Prisma Access prior to version 10.1.12

PAN-OS,Cloud NGFW,Prisma Access prior to version 9.1.17

PAN-OS,Cloud NGFW,Prisma Access prior to version 9.0.17-h4

 

Resolved Vulnerabilities

 

Password trapping vulnerability in GlobalProtect App (CVE-2024-2431, CVSS 5.7) [1]

Vulnerability in GlobalProtect App that allows local users to execute programs with elevated privileges (CVE-2024-2432, CVSS 5.2) [2]

An authorization vulnerability in PAN-OS, Cloud NGFW, and Prisma Access could allow an authenticated, read-only administrator to upload files using the web interface and completely fill one of the disk partitions with the uploaded files (CVE-2024-2433, CVSS 5.1) [3]

 

Vulnerability Patches

 

The 03/13/2024 update provided the following product-specific Vulnerability Patches

GlobalProtect App All

GlobalProtect App 6.1.1 and later versions

GlobalProtect App 6.0.4 and later versions

GlobalProtect App 5.2.13 and later versions

GlobalProtect App 5.1.12 and later versions

GlobalProtect App 6.2.1 and later versions

GlobalProtect App 6.1.2 and later versions

GlobalProtect App 6.0.8 and later versions

GlobalProtect App 5.1.12 and later versions

PAN-OS,Cloud NGFW,Prisma Access all versions

PAN-OS,Cloud NGFW,Prisma Access all versions

PAN-OS,Cloud NGFW,Prisma Access 11.0.3 and later versions

PAN-OS,Cloud NGFW,Prisma Access 10.2.8 and later versions

PAN-OS,Cloud NGFW,Prisma Access 10.1.12 and later

PAN-OS,Cloud NGFW,Prisma Access 9.1.17 and later versions

PAN-OS,Cloud NGFW,Prisma Access 9.0.17-h4 and later

PAN-OS,Cloud NGFW,Prisma Access all versions

 

Referenced Sites

 

[1] GlobalProtect App: Local User Can Disable GlobalProtect

https://security.paloaltonetworks.com/CVE-2024-2431

[2] GlobalProtect App: Local Privilege Escalation (PE) Vulnerability

https://security.paloaltonetworks.com/CVE-2024-2432

[3] PAN-OS: Improper Privilege Management Vulnerability in Panorama Software Leads to Availability Loss

https://security.paloaltonetworks.com/CVE-2024-2433