Authentication bypass vulnerabilities in the GlobalProtect portal and gateway of Palo Alto Networks PAN-OSĀ® software allows the attacker to bypass security restrictions and establish an unauthorized VPN connection.
Panorama and Cloud NGFW are not impacted by these issues.
The product relies on the existence or values of cookies when performing security-critical operations, but it does not properly ensure that the setting is valid for the associated user.
| Name | Vendor | Start Version | End Version |
|---|---|---|---|
| Pan-os | Paloaltonetworks | * | 10.2.7 (excluding) |
| Pan-os | Paloaltonetworks | 10.2.7 (including) | 10.2.7 (including) |
| Pan-os | Paloaltonetworks | 10.2.7-h1 (including) | 10.2.7-h1 (including) |
| Pan-os | Paloaltonetworks | 10.2.7-h12 (including) | 10.2.7-h12 (including) |
| Pan-os | Paloaltonetworks | 10.2.7-h16 (including) | 10.2.7-h16 (including) |
| Pan-os | Paloaltonetworks | 10.2.7-h18 (including) | 10.2.7-h18 (including) |
| Pan-os | Paloaltonetworks | 10.2.7-h19 (including) | 10.2.7-h19 (including) |
| Pan-os | Paloaltonetworks | 10.2.7-h21 (including) | 10.2.7-h21 (including) |
| Pan-os | Paloaltonetworks | 10.2.7-h24 (including) | 10.2.7-h24 (including) |
| Pan-os | Paloaltonetworks | 10.2.7-h3 (including) | 10.2.7-h3 (including) |
| Pan-os | Paloaltonetworks | 10.2.7-h32 (including) | 10.2.7-h32 (including) |
| Pan-os | Paloaltonetworks | 10.2.7-h6 (including) | 10.2.7-h6 (including) |
| Pan-os | Paloaltonetworks | 10.2.7-h8 (including) | 10.2.7-h8 (including) |
| Pan-os | Paloaltonetworks | 10.2.8 (including) | 10.2.8 (including) |
| Pan-os | Paloaltonetworks | 10.2.9 (including) | 10.2.9 (including) |
| Pan-os | Paloaltonetworks | 10.2.10 (including) | 10.2.10 (including) |
| Pan-os | Paloaltonetworks | 10.2.10-h10 (including) | 10.2.10-h10 (including) |
| Pan-os | Paloaltonetworks | 10.2.10-h12 (including) | 10.2.10-h12 (including) |
| Pan-os | Paloaltonetworks | 10.2.10-h14 (including) | 10.2.10-h14 (including) |
| Pan-os | Paloaltonetworks | 10.2.10-h17 (including) | 10.2.10-h17 (including) |
| Pan-os | Paloaltonetworks | 10.2.10-h18 (including) | 10.2.10-h18 (including) |
| Pan-os | Paloaltonetworks | 10.2.10-h2 (including) | 10.2.10-h2 (including) |
| Pan-os | Paloaltonetworks | 10.2.10-h21 (including) | 10.2.10-h21 (including) |
| Pan-os | Paloaltonetworks | 10.2.10-h27 (including) | 10.2.10-h27 (including) |
| Pan-os | Paloaltonetworks | 10.2.10-h3 (including) | 10.2.10-h3 (including) |
| Pan-os | Paloaltonetworks | 10.2.10-h30 (including) | 10.2.10-h30 (including) |
| Pan-os | Paloaltonetworks | 10.2.10-h31 (including) | 10.2.10-h31 (including) |
| Pan-os | Paloaltonetworks | 10.2.10-h4 (including) | 10.2.10-h4 (including) |
| Pan-os | Paloaltonetworks | 10.2.10-h5 (including) | 10.2.10-h5 (including) |
| Pan-os | Paloaltonetworks | 10.2.10-h7 (including) | 10.2.10-h7 (including) |
| Pan-os | Paloaltonetworks | 10.2.10-h9 (including) | 10.2.10-h9 (including) |
| Pan-os | Paloaltonetworks | 10.2.11 (including) | 10.2.11 (including) |
| Pan-os | Paloaltonetworks | 10.2.12 (including) | 10.2.12 (including) |
| Pan-os | Paloaltonetworks | 10.2.13 (including) | 10.2.13 (including) |
| Pan-os | Paloaltonetworks | 10.2.13-h1 (including) | 10.2.13-h1 (including) |
| Pan-os | Paloaltonetworks | 10.2.13-h10 (including) | 10.2.13-h10 (including) |
| Pan-os | Paloaltonetworks | 10.2.13-h16 (including) | 10.2.13-h16 (including) |
| Pan-os | Paloaltonetworks | 10.2.13-h18 (including) | 10.2.13-h18 (including) |
| Pan-os | Paloaltonetworks | 10.2.13-h2 (including) | 10.2.13-h2 (including) |
| Pan-os | Paloaltonetworks | 10.2.13-h3 (including) | 10.2.13-h3 (including) |
| Pan-os | Paloaltonetworks | 10.2.13-h4 (including) | 10.2.13-h4 (including) |
| Pan-os | Paloaltonetworks | 10.2.13-h5 (including) | 10.2.13-h5 (including) |
| Pan-os | Paloaltonetworks | 10.2.13-h7 (including) | 10.2.13-h7 (including) |
| Pan-os | Paloaltonetworks | 10.2.14 (including) | 10.2.14 (including) |
| Pan-os | Paloaltonetworks | 10.2.15 (including) | 10.2.15 (including) |
| Pan-os | Paloaltonetworks | 10.2.16 (including) | 10.2.16 (including) |
| Pan-os | Paloaltonetworks | 10.2.16-h1 (including) | 10.2.16-h1 (including) |
| Pan-os | Paloaltonetworks | 10.2.16-h4 (including) | 10.2.16-h4 (including) |
| Pan-os | Paloaltonetworks | 10.2.16-h6 (including) | 10.2.16-h6 (including) |
| Pan-os | Paloaltonetworks | 10.2.17 (including) | 10.2.17 (including) |
| Pan-os | Paloaltonetworks | 10.2.18 (including) | 10.2.18 (including) |
| Pan-os | Paloaltonetworks | 10.2.18-h1 (including) | 10.2.18-h1 (including) |
| Pan-os | Paloaltonetworks | 10.2.18-h5 (including) | 10.2.18-h5 (including) |
| Pan-os | Paloaltonetworks | 11.1.0 (including) | 11.1.0 (including) |
| Pan-os | Paloaltonetworks | 11.1.1 (including) | 11.1.1 (including) |
| Pan-os | Paloaltonetworks | 11.1.2 (including) | 11.1.2 (including) |
| Pan-os | Paloaltonetworks | 11.1.3 (including) | 11.1.3 (including) |
| Pan-os | Paloaltonetworks | 11.1.4 (including) | 11.1.4 (including) |
| Pan-os | Paloaltonetworks | 11.1.4-h1 (including) | 11.1.4-h1 (including) |
| Pan-os | Paloaltonetworks | 11.1.4-h13 (including) | 11.1.4-h13 (including) |
| Pan-os | Paloaltonetworks | 11.1.4-h15 (including) | 11.1.4-h15 (including) |
| Pan-os | Paloaltonetworks | 11.1.4-h16 (including) | 11.1.4-h16 (including) |
| Pan-os | Paloaltonetworks | 11.1.4-h17 (including) | 11.1.4-h17 (including) |
| Pan-os | Paloaltonetworks | 11.1.4-h18 (including) | 11.1.4-h18 (including) |
| Pan-os | Paloaltonetworks | 11.1.4-h25 (including) | 11.1.4-h25 (including) |
| Pan-os | Paloaltonetworks | 11.1.4-h27 (including) | 11.1.4-h27 (including) |
| Pan-os | Paloaltonetworks | 11.1.4-h32 (including) | 11.1.4-h32 (including) |
| Pan-os | Paloaltonetworks | 11.1.4-h4 (including) | 11.1.4-h4 (including) |
| Pan-os | Paloaltonetworks | 11.1.4-h7 (including) | 11.1.4-h7 (including) |
| Pan-os | Paloaltonetworks | 11.1.4-h9 (including) | 11.1.4-h9 (including) |
| Pan-os | Paloaltonetworks | 11.1.5 (including) | 11.1.5 (including) |
| Pan-os | Paloaltonetworks | 11.1.6 (including) | 11.1.6 (including) |
| Pan-os | Paloaltonetworks | 11.1.6-h1 (including) | 11.1.6-h1 (including) |
| Pan-os | Paloaltonetworks | 11.1.6-h10 (including) | 11.1.6-h10 (including) |
| Pan-os | Paloaltonetworks | 11.1.6-h14 (including) | 11.1.6-h14 (including) |
| Pan-os | Paloaltonetworks | 11.1.6-h17 (including) | 11.1.6-h17 (including) |
| Pan-os | Paloaltonetworks | 11.1.6-h19 (including) | 11.1.6-h19 (including) |
| Pan-os | Paloaltonetworks | 11.1.6-h2 (including) | 11.1.6-h2 (including) |
| Pan-os | Paloaltonetworks | 11.1.6-h20 (including) | 11.1.6-h20 (including) |
| Pan-os | Paloaltonetworks | 11.1.6-h21 (including) | 11.1.6-h21 (including) |
| Pan-os | Paloaltonetworks | 11.1.6-h22 (including) | 11.1.6-h22 (including) |
| Pan-os | Paloaltonetworks | 11.1.6-h23 (including) | 11.1.6-h23 (including) |
| Pan-os | Paloaltonetworks | 11.1.6-h25 (including) | 11.1.6-h25 (including) |
| Pan-os | Paloaltonetworks | 11.1.6-h29 (including) | 11.1.6-h29 (including) |
| Pan-os | Paloaltonetworks | 11.1.6-h3 (including) | 11.1.6-h3 (including) |
| Pan-os | Paloaltonetworks | 11.1.6-h4 (including) | 11.1.6-h4 (including) |
| Pan-os | Paloaltonetworks | 11.1.6-h5 (including) | 11.1.6-h5 (including) |
| Pan-os | Paloaltonetworks | 11.1.6-h6 (including) | 11.1.6-h6 (including) |
| Pan-os | Paloaltonetworks | 11.1.6-h7 (including) | 11.1.6-h7 (including) |
| Pan-os | Paloaltonetworks | 11.1.7 (including) | 11.1.7 (including) |
| Pan-os | Paloaltonetworks | 11.1.7-h1 (including) | 11.1.7-h1 (including) |
| Pan-os | Paloaltonetworks | 11.1.7-h2 (including) | 11.1.7-h2 (including) |
| Pan-os | Paloaltonetworks | 11.1.7-h4 (including) | 11.1.7-h4 (including) |
| Pan-os | Paloaltonetworks | 11.1.8 (including) | 11.1.8 (including) |
| Pan-os | Paloaltonetworks | 11.1.9 (including) | 11.1.9 (including) |
| Pan-os | Paloaltonetworks | 11.1.10 (including) | 11.1.10 (including) |
| Pan-os | Paloaltonetworks | 11.1.10-h1 (including) | 11.1.10-h1 (including) |
| Pan-os | Paloaltonetworks | 11.1.10-h10 (including) | 11.1.10-h10 (including) |
| Pan-os | Paloaltonetworks | 11.1.10-h12 (including) | 11.1.10-h12 (including) |
| Pan-os | Paloaltonetworks | 11.1.10-h21 (including) | 11.1.10-h21 (including) |
| Pan-os | Paloaltonetworks | 11.1.10-h4 (including) | 11.1.10-h4 (including) |
| Pan-os | Paloaltonetworks | 11.1.10-h5 (including) | 11.1.10-h5 (including) |
| Pan-os | Paloaltonetworks | 11.1.10-h7 (including) | 11.1.10-h7 (including) |
| Pan-os | Paloaltonetworks | 11.1.10-h9 (including) | 11.1.10-h9 (including) |
| Pan-os | Paloaltonetworks | 11.1.11 (including) | 11.1.11 (including) |
| Pan-os | Paloaltonetworks | 11.1.12 (including) | 11.1.12 (including) |
| Pan-os | Paloaltonetworks | 11.1.13 (including) | 11.1.13 (including) |
| Pan-os | Paloaltonetworks | 11.1.13-h1 (including) | 11.1.13-h1 (including) |
| Pan-os | Paloaltonetworks | 11.1.13-h2 (including) | 11.1.13-h2 (including) |
| Pan-os | Paloaltonetworks | 11.1.13-h3 (including) | 11.1.13-h3 (including) |
| Pan-os | Paloaltonetworks | 11.1.14 (including) | 11.1.14 (including) |
| Pan-os | Paloaltonetworks | 11.2.0 (including) | 11.2.0 (including) |
| Pan-os | Paloaltonetworks | 11.2.1 (including) | 11.2.1 (including) |
| Pan-os | Paloaltonetworks | 11.2.2 (including) | 11.2.2 (including) |
| Pan-os | Paloaltonetworks | 11.2.3 (including) | 11.2.3 (including) |
| Pan-os | Paloaltonetworks | 11.2.4 (including) | 11.2.4 (including) |
| Pan-os | Paloaltonetworks | 11.2.4-h1 (including) | 11.2.4-h1 (including) |
| Pan-os | Paloaltonetworks | 11.2.4-h10 (including) | 11.2.4-h10 (including) |
| Pan-os | Paloaltonetworks | 11.2.4-h11 (including) | 11.2.4-h11 (including) |
| Pan-os | Paloaltonetworks | 11.2.4-h12 (including) | 11.2.4-h12 (including) |
| Pan-os | Paloaltonetworks | 11.2.4-h14 (including) | 11.2.4-h14 (including) |
| Pan-os | Paloaltonetworks | 11.2.4-h15 (including) | 11.2.4-h15 (including) |
| Pan-os | Paloaltonetworks | 11.2.4-h2 (including) | 11.2.4-h2 (including) |
| Pan-os | Paloaltonetworks | 11.2.4-h4 (including) | 11.2.4-h4 (including) |
| Pan-os | Paloaltonetworks | 11.2.4-h5 (including) | 11.2.4-h5 (including) |
| Pan-os | Paloaltonetworks | 11.2.4-h6 (including) | 11.2.4-h6 (including) |
| Pan-os | Paloaltonetworks | 11.2.4-h7 (including) | 11.2.4-h7 (including) |
| Pan-os | Paloaltonetworks | 11.2.4-h8 (including) | 11.2.4-h8 (including) |
| Pan-os | Paloaltonetworks | 11.2.4-h9 (including) | 11.2.4-h9 (including) |
| Pan-os | Paloaltonetworks | 11.2.5 (including) | 11.2.5 (including) |
| Pan-os | Paloaltonetworks | 11.2.6 (including) | 11.2.6 (including) |
| Pan-os | Paloaltonetworks | 11.2.7 (including) | 11.2.7 (including) |
| Pan-os | Paloaltonetworks | 11.2.7-h1 (including) | 11.2.7-h1 (including) |
| Pan-os | Paloaltonetworks | 11.2.7-h10 (including) | 11.2.7-h10 (including) |
| Pan-os | Paloaltonetworks | 11.2.7-h11 (including) | 11.2.7-h11 (including) |
| Pan-os | Paloaltonetworks | 11.2.7-h12 (including) | 11.2.7-h12 (including) |
| Pan-os | Paloaltonetworks | 11.2.7-h13 (including) | 11.2.7-h13 (including) |
| Pan-os | Paloaltonetworks | 11.2.7-h2 (including) | 11.2.7-h2 (including) |
| Pan-os | Paloaltonetworks | 11.2.7-h3 (including) | 11.2.7-h3 (including) |
| Pan-os | Paloaltonetworks | 11.2.7-h4 (including) | 11.2.7-h4 (including) |
| Pan-os | Paloaltonetworks | 11.2.7-h7 (including) | 11.2.7-h7 (including) |
| Pan-os | Paloaltonetworks | 11.2.7-h8 (including) | 11.2.7-h8 (including) |
| Pan-os | Paloaltonetworks | 11.2.8 (including) | 11.2.8 (including) |
| Pan-os | Paloaltonetworks | 11.2.9 (including) | 11.2.9 (including) |
| Pan-os | Paloaltonetworks | 11.2.10 (including) | 11.2.10 (including) |
| Pan-os | Paloaltonetworks | 11.2.10-h1 (including) | 11.2.10-h1 (including) |
| Pan-os | Paloaltonetworks | 11.2.10-h2 (including) | 11.2.10-h2 (including) |
| Pan-os | Paloaltonetworks | 11.2.10-h3 (including) | 11.2.10-h3 (including) |
| Pan-os | Paloaltonetworks | 11.2.10-h4 (including) | 11.2.10-h4 (including) |
| Pan-os | Paloaltonetworks | 11.2.10-h5 (including) | 11.2.10-h5 (including) |
| Pan-os | Paloaltonetworks | 11.2.10-h6 (including) | 11.2.10-h6 (including) |
| Pan-os | Paloaltonetworks | 11.2.11 (including) | 11.2.11 (including) |
| Pan-os | Paloaltonetworks | 12.1.2 (including) | 12.1.2 (including) |
| Pan-os | Paloaltonetworks | 12.1.3 (including) | 12.1.3 (including) |
| Pan-os | Paloaltonetworks | 12.1.4 (including) | 12.1.4 (including) |
| Pan-os | Paloaltonetworks | 12.1.4-h2 (including) | 12.1.4-h2 (including) |
| Pan-os | Paloaltonetworks | 12.1.4-h3 (including) | 12.1.4-h3 (including) |
| Pan-os | Paloaltonetworks | 12.1.4-h5 (including) | 12.1.4-h5 (including) |
| Pan-os | Paloaltonetworks | 12.1.5 (including) | 12.1.5 (including) |
| Pan-os | Paloaltonetworks | 12.1.6 (including) | 12.1.6 (including) |