A vulnerability in how Palo Alto Networks PAN-OS software processes data received from Cloud Identity Engine (CIE) agents enables modification of User-ID groups. This impacts user access to network resources where users may be inappropriately denied or allowed access to resources based on your existing Security Policy rules.
2024-04-10T17:15:57.000
2025-01-24T15:29:26.313
Analyzed
CVSSv3.1: 7.4 (HIGH)
Type | Vendor | Product | Version/Range | Vulnerable? |
---|---|---|---|---|
Operating System | paloaltonetworks | pan-os | < 10.1.11 | Yes |
Operating System | paloaltonetworks | pan-os | < 10.2.5 | Yes |
Operating System | paloaltonetworks | pan-os | < 11.0.3 | Yes |