VYPR
Medium severity4.3NVD Advisory· Published Nov 14, 2024· Updated Jun 17, 2026

CVE-2024-5918

CVE-2024-5918

Description

An improper certificate validation vulnerability in Palo Alto Networks PAN-OS software enables an authorized user with a specially crafted client certificate to connect to an impacted GlobalProtect portal or GlobalProtect gateway as a different legitimate user. This attack is possible only if you "Allow Authentication with User Credentials OR Client Certificate."

AI Insight

LLM-synthesized narrative grounded in this CVE's description and references.

Affected products

9
  • cpe:2.3:o:paloaltonetworks:pan-os:*:*:*:*:*:*:*:*+ 6 more
    • cpe:2.3:o:paloaltonetworks:pan-os:*:*:*:*:*:*:*:*range: >=10.1.0,<10.1.11
    • cpe:2.3:o:paloaltonetworks:pan-os:10.2.4:-:*:*:*:*:*:*
    • cpe:2.3:o:paloaltonetworks:pan-os:10.2.4:h2:*:*:*:*:*:*
    • cpe:2.3:o:paloaltonetworks:pan-os:10.2.4:h3:*:*:*:*:*:*
    • cpe:2.3:o:paloaltonetworks:pan-os:10.2.4:h4:*:*:*:*:*:*
    • cpe:2.3:o:paloaltonetworks:pan-os:11.0.2:h4:*:*:*:*:*:*range: 11.0.0
    • (no CPE)
  • Range: All

Patches

Vulnerability mechanics

References

1

News mentions

0

No linked articles in our index yet.