« Volver al listado

CVE-2024-0009

Estado: AnalizadaMedia (6.3)—

An improper verification vulnerability in the GlobalProtect gateway feature of Palo Alto Networks PAN-OS software enables a malicious user with stolen credentials to establish a VPN connection from an unauthorized IP address.

CVSS

Probabilidad de explotación (EPSS)

EPSS (Exploit Prediction Scoring System, de FIRST) estima la probabilidad de que una vulnerabilidad sea explotada en 30 días. Complementa a CVSS (impacto) y a CISA KEV (explotación confirmada).

Tecnologías afectadas (1)

CWE

Referencias

JSON original (NVD)

Mostrar
{
  "id": "CVE-2024-0009",
  "cveTags": [],
  "metrics": {
    "ssvcV203": [
      {
        "source": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
        "ssvcData": {
          "id": "CVE-2024-0009",
          "role": "CISA Coordinator",
          "options": [
            {
              "exploitation": "none"
            },
            {
              "automatable": "no"
            },
            {
              "technicalImpact": "partial"
            }
          ],
          "version": "2.0.3",
          "timestamp": "2024-02-15T20:06:19.062126Z"
        }
      }
    ],
    "cvssMetricV31": [
      {
        "type": "Secondary",
        "source": "psirt@paloaltonetworks.com",
        "cvssData": {
          "scope": "UNCHANGED",
          "version": "3.1",
          "baseScore": 6.3,
          "attackVector": "NETWORK",
          "baseSeverity": "MEDIUM",
          "vectorString": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L",
          "integrityImpact": "LOW",
          "userInteraction": "NONE",
          "attackComplexity": "LOW",
          "availabilityImpact": "LOW",
          "privilegesRequired": "LOW",
          "confidentialityImpact": "LOW"
        },
        "impactScore": 3.4,
        "exploitabilityScore": 2.8
      },
      {
        "type": "Primary",
        "source": "nvd@nist.gov",
        "cvssData": {
          "scope": "UNCHANGED",
          "version": "3.1",
          "baseScore": 6.3,
          "attackVector": "NETWORK",
          "baseSeverity": "MEDIUM",
          "vectorString": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L",
          "integrityImpact": "LOW",
          "userInteraction": "NONE",
          "attackComplexity": "LOW",
          "availabilityImpact": "LOW",
          "privilegesRequired": "LOW",
          "confidentialityImpact": "LOW"
        },
        "impactScore": 3.4,
        "exploitabilityScore": 2.8
      }
    ]
  },
  "affected": [
    {
      "source": "psirt@paloaltonetworks.com",
      "affectedData": [
        {
          "vendor": "Palo Alto Networks",
          "product": "PAN-OS",
          "versions": [
            {
              "status": "unaffected",
              "version": "9.0"
            },
            {
              "status": "unaffected",
              "version": "9.1"
            },
            {
              "status": "unaffected",
              "version": "10.1"
            },
            {
              "status": "affected",
              "changes": [
                {
                  "at": "10.2.4",
                  "status": "unaffected"
                }
              ],
              "version": "10.2",
              "lessThan": "10.2.4",
              "versionType": "custom"
            },
            {
              "status": "affected",
              "changes": [
                {
                  "at": "11.0.1",
                  "status": "unaffected"
                }
              ],
              "version": "11.0",
              "lessThan": "11.0.1",
              "versionType": "custom"
            },
            {
              "status": "unaffected",
              "version": "11.1"
            }
          ],
          "defaultStatus": "unaffected"
        },
        {
          "vendor": "Palo Alto Networks",
          "product": "Prisma Access",
          "versions": [
            {
              "status": "unaffected",
              "version": "All"
            }
          ],
          "defaultStatus": "unaffected"
        },
        {
          "vendor": "Palo Alto Networks",
          "product": "Cloud NGFW",
          "versions": [
            {
              "status": "unaffected",
              "version": "All"
            }
          ],
          "defaultStatus": "unaffected"
        }
      ]
    }
  ],
  "published": "2024-02-14T18:15:47.503",
  "references": [
    {
      "url": "https://security.paloaltonetworks.com/CVE-2024-0009",
      "tags": [
        "Vendor Advisory"
      ],
      "source": "psirt@paloaltonetworks.com"
    },
    {
      "url": "https://security.paloaltonetworks.com/CVE-2024-0009",
      "tags": [
        "Vendor Advisory"
      ],
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    }
  ],
  "vulnStatus": "Analyzed",
  "weaknesses": [
    {
      "type": "Secondary",
      "source": "psirt@paloaltonetworks.com",
      "description": [
        {
          "lang": "en",
          "value": "CWE-940"
        }
      ]
    },
    {
      "type": "Primary",
      "source": "nvd@nist.gov",
      "description": [
        {
          "lang": "en",
          "value": "CWE-346"
        }
      ]
    }
  ],
  "descriptions": [
    {
      "lang": "en",
      "value": "An improper verification vulnerability in the GlobalProtect gateway feature of Palo Alto Networks PAN-OS software enables a malicious user with stolen credentials to establish a VPN connection from an unauthorized IP address."
    },
    {
      "lang": "es",
      "value": "Una vulnerabilidad de verificación incorrecta en la función de puerta de enlace GlobalProtect del software PAN-OS de Palo Alto Networks permite a un usuario malintencionado con credenciales robadas establecer una conexión VPN desde una dirección IP no autorizada."
    }
  ],
  "lastModified": "2026-06-17T06:52:35.600",
  "configurations": [
    {
      "nodes": [
        {
          "negate": false,
          "cpeMatch": [
            {
              "criteria": "cpe:2.3:o:paloaltonetworks:pan-os:11.0.0:-:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "8BB72E15-486F-491F-A08D-E1AC2C8AB121"
            },
            {
              "criteria": "cpe:2.3:o:paloaltonetworks:pan-os:11.0.0:h1:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "B5E7EFD5-2179-45BF-BF5B-197B66903D9C"
            },
            {
              "criteria": "cpe:2.3:o:paloaltonetworks:pan-os:11.0.0:h2:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "3EF4AE4F-36F3-4923-AE1E-DE9E036D4E2F"
            },
            {
              "criteria": "cpe:2.3:o:paloaltonetworks:pan-os:11.0.0:h3:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "10587864-8777-40F9-B162-BFBFAB8F5E06"
            },
            {
              "criteria": "cpe:2.3:o:paloaltonetworks:pan-os:11.0.0:h4:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "BA374C05-F547-481C-98B4-8F03DD7AB4E1"
            }
          ],
          "operator": "OR"
        }
      ]
    },
    {
      "nodes": [
        {
          "negate": false,
          "cpeMatch": [
            {
              "criteria": "cpe:2.3:o:paloaltonetworks:pan-os:*:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "D61F01F8-1598-4078-9D98-BFF5B62F3BA5",
              "versionEndExcluding": "10.2.4",
              "versionStartIncluding": "10.2.0"
            }
          ],
          "operator": "OR"
        }
      ]
    }
  ],
  "sourceIdentifier": "psirt@paloaltonetworks.com"
}