CVE Vulnerabilities

CVE-2024-3383

Improper Ownership Management

Published: Apr 10, 2024 | Modified: Jan 24, 2025
CVSS 3.x
9.1
CRITICAL
Source:
NVD
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:H
CVSS 2.x
RedHat/V2
RedHat/V3
Ubuntu

A vulnerability in how Palo Alto Networks PAN-OS software processes data received from Cloud Identity Engine (CIE) agents enables modification of User-ID groups. This impacts user access to network resources where users may be inappropriately denied or allowed access to resources based on your existing Security Policy rules.

Weakness

The product assigns the wrong ownership, or does not properly verify the ownership, of an object or resource.

Affected Software

Name Vendor Start Version End Version
Pan-os Paloaltonetworks 10.1.0 (including) 10.1.11 (excluding)
Pan-os Paloaltonetworks 10.2.0 (including) 10.2.5 (excluding)
Pan-os Paloaltonetworks 11.0.0 (including) 11.0.3 (excluding)

Potential Mitigations

References