Palo Alto Networks GlobalProtect App
cpe:2.3:a:paloaltonetworks:globalprotect:*:*:*:*:*:*:*
- >= 6.3.0, < 6.3.3-h2 (6.3.3-c676)
- >= 6.2.0, < 6.2.8-h3 (6.2.8-c263)
- >= 6.1
- >= 6.0
A vulnerability has been identified in the Palo Alto Networks GlobalProtect app, specifically in versions 6.0.0, 6.1.0, 6.2.0 prior to 6.2.8-h3, 6.3.0 prior to 6.3.3-h2 on Windows, and 6.3.0 prior to 6.3.3 on Linux. This vulnerability arises from insufficient certificate validation, which allows attackers to connect the GlobalProtect app to arbitrary servers. As a result, a local non-administrative user or an attacker on the same subnet could install malicious root certificates on the endpoint. This would enable the installation of malicious software signed by the fraudulent root certificates.
Exploitation of this vulnerability could lead to unauthorized installation of root certificates, allowing for the subsequent installation of malicious software disguised as legitimate, potentially bypassing security measures.
Users can upgrade to GlobalProtect App 6.3.3-h2 or 6.2.8-h3 on Windows, or GlobalProtect App 6.3.3 or 6.2.8 on Linux. After upgrading, ensure that the portal/gateway certificate can be validated using the operating system's certificate store, remove any certificates associated with portal/gateway validation from the 'Trusted Root CA' list on the Portal, and enable the portal setting 'Enable Strict Certificate Check'.
Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.