GlobalProtect Agent 4.1.0 for Windows and GlobalProtect Agent 4.1.10 and earlier for macOS may allow a local authenticated attacker who has compromised the end-user account and gained the ability to inspect memory, to access authentication and/or session tokens and replay them to spoof the VPN session and gain access as the user.
2019-04-09T22:29:00.877
2024-11-21T04:36:50.333
Modified
CVSSv3.1: 2.5 (LOW)
AV:L/AC:M/Au:N/C:P/I:N/A:N
3.4
2.9
Type | Vendor | Product | Version/Range | Vulnerable? |
---|---|---|---|---|
Application | paloaltonetworks | globalprotect | ≤ 4.1.0 | Yes |
Application | paloaltonetworks | globalprotect | ≤ 4.1.10 | Yes |