An improper certificate validation vulnerability in Palo Alto Networks PAN-OS software enables an authorized user with a specially crafted client certificate to connect to an impacted GlobalProtect portal or GlobalProtect gateway as a different legitimate user. This attack is possible only if you "Allow Authentication with User Credentials OR Client Certificate."
| Software | From | Fixed in |
|---|---|---|
| paloaltonetworks / pan-os | 10.1.0 | 10.1.11 |
| paloaltonetworks / pan-os | 10.2.0 | 10.2.4.x |
| paloaltonetworks / pan-os | 11.0.0 | 11.0.3 |
| paloaltonetworks / pan-os | 10.2.4 | 10.2.4.x |
| paloaltonetworks / pan-os | 10.2.4-h2 | 10.2.4-h2.x |
| paloaltonetworks / pan-os | 10.2.4-h3 | 10.2.4-h3.x |
| paloaltonetworks / pan-os | 10.2.4-h4 | 10.2.4-h4.x |