CVE Vulnerabilities

CVE-2024-2431

Improper Privilege Management

Published: Mar 13, 2024 | Modified: Sep 26, 2025
CVSS 3.x
N/A
Source:
NVD
CVSS 2.x
RedHat/V2
RedHat/V3
Ubuntu

An issue in the Palo Alto Networks GlobalProtect app enables a non-privileged user to disable the GlobalProtect app in configurations that allow a user to disable GlobalProtect with a passcode.

Weakness

The product does not properly assign, modify, track, or check privileges for an actor, creating an unintended sphere of control for that actor.

Affected Software

Name Vendor Start Version End Version
Globalprotect Paloaltonetworks 5.1.0 (including) 5.1.12 (excluding)
Globalprotect Paloaltonetworks 5.2.0 (including) 5.2.13 (including)
Globalprotect Paloaltonetworks 6.0.0 (including) 6.0.4 (excluding)
Globalprotect Paloaltonetworks 6.1.0 (including) 6.1.0 (including)

Potential Mitigations

References