Multiple vulnerabilities were identified in Palo Alto Products. A remote attacker could exploit some of these vulnerabilities to trigger elevation of privilege, denial of service condition, remote code execution and cross-site scripting on the targeted system.
System / Technologies affected
Cloud NGFW all versions on AWS and Azure
GlobalProtect App 6.0 versions earlier than 6.0.15 on macOS, Linux and Windows
GlobalProtect App 6.2 versions earlier than 6.2.8-h14 on macOS and Windows
GlobalProtect App 6.3 versions earlier than 6.3.3-h15 on macOS, Linux and Windows
GlobalProtect App all versions on iOS, Android, ChromeOS
PAN-OS 10.2 versions earlier than 10.2.7-h37
PAN-OS 10.2 versions earlier than 10.2.10-h40
PAN-OS 10.2 versions earlier than 10.2.13-h24
PAN-OS 10.2 versions earlier than 10.2.16-h10
PAN-OS 10.2 versions earlier than 10.2.18-h10
PAN-OS 11.1 versions earlier than 11.1.4-h36
PAN-OS 11.1 versions earlier than 11.1.6-h38
PAN-OS 11.1 versions earlier than 11.1.7-h10
PAN-OS 11.1 versions earlier than 11.1.10-h33
PAN-OS 11.1 versions earlier than 11.1.13-h12
PAN-OS 11.1 versions earlier than 11.1.16-h2
PAN-OS 11.2 versions earlier than 11.2.4-h21
PAN-OS 11.2 versions earlier than 11.2.7-h20
PAN-OS 11.2 versions earlier than 11.2.10-h14
PAN-OS 11.2 versions earlier than 11.2.13-h2
PAN-OS 12.1 versions earlier than 12.1.4-h10
PAN-OS 12.1 versions earlier than 12.1.7-h5
PAN-OS 12.1 versions earlier than 12.1.10
PAN-OS 12.2 versions earlier than 12.2.3
Prisma Access 10.2 versions earlier than 10.2.10-h40
Prisma Access 11.2 versions earlier than 11.2.7-h20
Prisma Access 12.1 versions earlier than 12.1.7-h5
Before installation of the software, please visit the vendor web-site for more details.
Apply fixes issued by the vendor:
Vulnerability Identifier
The full story
This article is one source in a clustered incident — the cluster page carries the summary, timeline and every other outlet covering it.
