An improper verification vulnerability in the GlobalProtect gateway feature of Palo Alto Networks PAN-OS software enables a malicious user with stolen credentials to establish a VPN connection from an unauthorized IP address.
Solution:
The product establishes a communication channel to handle an incoming request that has been initiated by an actor, but it does not properly verify that the request is coming from the expected origin.
The product does not properly verify that the source of data or communication is valid.
Link | Tags |
---|---|
https://security.paloaltonetworks.com/CVE-2024-0009 | vendor advisory |