CVE Vulnerabilities

CVE-2024-2431

Improper Privilege Management

Published: Mar 13, 2024 | Modified: Sep 26, 2025
CVSS 3.x
N/A
Source:
NVD
CVSS 2.x
RedHat/V2
RedHat/V3
Ubuntu
root.io logo minimus.io logo echo.ai logo

An issue in the Palo Alto Networks GlobalProtect app enables a non-privileged user to disable the GlobalProtect app in configurations that allow a user to disable GlobalProtect with a passcode.

Weakness

The product does not properly assign, modify, track, or check privileges for an actor, creating an unintended sphere of control for that actor.

Affected Software

NameVendorStart VersionEnd Version
GlobalprotectPaloaltonetworks5.1.0 (including)5.1.12 (excluding)
GlobalprotectPaloaltonetworks5.2.0 (including)5.2.13 (including)
GlobalprotectPaloaltonetworks6.0.0 (including)6.0.4 (excluding)
GlobalprotectPaloaltonetworks6.1.0 (including)6.1.0 (including)

Potential Mitigations

References