CVE-2024-0010
Estado: AnalizadaMedia (6.1)—
A reflected cross-site scripting (XSS) vulnerability in the GlobalProtect portal feature of Palo Alto Networks PAN-OS software enables execution of malicious JavaScript (in the context of a user’s browser) if a user clicks on a malicious link, allowing phishing attacks that could lead to credential theft.
CVSS
- Versión: 3.1
- Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N
- Puntuación base: 6.1
Probabilidad de explotación (EPSS)
- Probabilidad de explotación en los próximos 30 días: 0.51%
- Percentil entre todas las CVEs puntuadas: 42
- Fecha de la puntuación: 7/10/2026
EPSS (Exploit Prediction Scoring System, de FIRST) estima la probabilidad de que una vulnerabilidad sea explotada en 30 días. Complementa a CVSS (impacto) y a CISA KEV (explotación confirmada).
Tecnologías afectadas (1)
CWE
- CWE-79
- CWE-79
Referencias
JSON original (NVD)
Mostrar
{
"id": "CVE-2024-0010",
"cveTags": [],
"metrics": {
"ssvcV203": [
{
"source": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
"ssvcData": {
"id": "CVE-2024-0010",
"role": "CISA Coordinator",
"options": [
{
"exploitation": "none"
},
{
"automatable": "no"
},
{
"technicalImpact": "partial"
}
],
"version": "2.0.3",
"timestamp": "2024-02-15T16:39:09.757949Z"
}
}
],
"cvssMetricV31": [
{
"type": "Secondary",
"source": "psirt@paloaltonetworks.com",
"cvssData": {
"scope": "UNCHANGED",
"version": "3.1",
"baseScore": 4.3,
"attackVector": "NETWORK",
"baseSeverity": "MEDIUM",
"vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:N",
"integrityImpact": "LOW",
"userInteraction": "REQUIRED",
"attackComplexity": "LOW",
"availabilityImpact": "NONE",
"privilegesRequired": "NONE",
"confidentialityImpact": "NONE"
},
"impactScore": 1.4,
"exploitabilityScore": 2.8
},
{
"type": "Primary",
"source": "nvd@nist.gov",
"cvssData": {
"scope": "CHANGED",
"version": "3.1",
"baseScore": 6.1,
"attackVector": "NETWORK",
"baseSeverity": "MEDIUM",
"vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N",
"integrityImpact": "LOW",
"userInteraction": "REQUIRED",
"attackComplexity": "LOW",
"availabilityImpact": "NONE",
"privilegesRequired": "NONE",
"confidentialityImpact": "LOW"
},
"impactScore": 2.7,
"exploitabilityScore": 2.8
}
]
},
"affected": [
{
"source": "psirt@paloaltonetworks.com",
"affectedData": [
{
"vendor": "Palo Alto Networks",
"product": "PAN-OS",
"versions": [
{
"status": "affected",
"changes": [
{
"at": "9.0.17-h4",
"status": "unaffected"
}
],
"version": "9.0",
"lessThan": "9.0.17-h4",
"versionType": "custom"
},
{
"status": "affected",
"changes": [
{
"at": "9.1.17",
"status": "unaffected"
}
],
"version": "9.1",
"lessThan": "9.1.17",
"versionType": "custom"
},
{
"status": "affected",
"changes": [
{
"at": "10.1.11-h1",
"status": "unaffected"
}
],
"version": "10.1",
"lessThan": "10.1.11-h1",
"versionType": "custom"
},
{
"status": "affected",
"changes": [
{
"at": "10.1.12",
"status": "unaffected"
}
],
"version": "10.1",
"lessThan": "10.1.12",
"versionType": "custom"
},
{
"status": "unaffected",
"changes": [
{
"at": "11.0.1",
"status": "unaffected"
}
],
"version": "10.2",
"lessThan": "11.0.1",
"versionType": "custom"
},
{
"status": "unaffected",
"changes": [
{
"at": "10.1.10-h1",
"status": "unaffected"
}
],
"version": "11.0",
"lessThan": "10.1.10-h1",
"versionType": "custom"
},
{
"status": "unaffected",
"version": "11.1"
}
],
"defaultStatus": "unaffected"
},
{
"vendor": "Palo Alto Networks",
"product": "Prisma Access",
"versions": [
{
"status": "unaffected",
"version": "All"
}
],
"defaultStatus": "unaffected"
},
{
"vendor": "Palo Alto Networks",
"product": "Cloud NGFW",
"versions": [
{
"status": "unaffected",
"version": "All"
}
],
"defaultStatus": "unaffected"
}
]
}
],
"published": "2024-02-14T18:15:47.703",
"references": [
{
"url": "https://security.paloaltonetworks.com/CVE-2024-0010",
"tags": [
"Vendor Advisory"
],
"source": "psirt@paloaltonetworks.com"
},
{
"url": "https://security.paloaltonetworks.com/CVE-2024-0010",
"tags": [
"Vendor Advisory"
],
"source": "af854a3a-2127-422b-91ae-364da2661108"
}
],
"vulnStatus": "Analyzed",
"weaknesses": [
{
"type": "Secondary",
"source": "psirt@paloaltonetworks.com",
"description": [
{
"lang": "en",
"value": "CWE-79"
}
]
},
{
"type": "Primary",
"source": "nvd@nist.gov",
"description": [
{
"lang": "en",
"value": "CWE-79"
}
]
}
],
"descriptions": [
{
"lang": "en",
"value": "A reflected cross-site scripting (XSS) vulnerability in the GlobalProtect portal feature of Palo Alto Networks PAN-OS software enables execution of malicious JavaScript (in the context of a user’s browser) if a user clicks on a malicious link, allowing phishing attacks that could lead to credential theft."
},
{
"lang": "es",
"value": "Una vulnerabilidad de Cross-Site Scripting (XSS) reflejado en la función del portal GlobalProtect del software PAN-OS de Palo Alto Networks permite la ejecución de JavaScript malicioso (en el contexto del navegador de un usuario) si un usuario hace clic en un enlace malicioso, lo que permite ataques de phishing que podría provocar el robo de credenciales."
}
],
"lastModified": "2026-06-17T06:52:35.727",
"configurations": [
{
"nodes": [
{
"negate": false,
"cpeMatch": [
{
"criteria": "cpe:2.3:o:paloaltonetworks:pan-os:*:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "77695C8C-9732-4605-A160-A5159BD8B49C",
"versionEndExcluding": "10.1.11",
"versionStartIncluding": "10.1.0"
},
{
"criteria": "cpe:2.3:o:paloaltonetworks:pan-os:10.1.11:-:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "F6242E26-AF44-4A19-ADD3-CBB798A862D1"
}
],
"operator": "OR"
}
]
},
{
"nodes": [
{
"negate": false,
"cpeMatch": [
{
"criteria": "cpe:2.3:o:paloaltonetworks:pan-os:*:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "9F9FFBA6-7008-422B-9CF1-E37CA62081EB",
"versionEndExcluding": "9.1.17",
"versionStartIncluding": "9.1.0"
}
],
"operator": "OR"
}
]
},
{
"nodes": [
{
"negate": false,
"cpeMatch": [
{
"criteria": "cpe:2.3:o:paloaltonetworks:pan-os:*:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "89A55C5F-8E01-42C4-BE93-D683900C07BE",
"versionEndExcluding": "9.0.17",
"versionStartIncluding": "9.0.0"
},
{
"criteria": "cpe:2.3:o:paloaltonetworks:pan-os:9.0.17:-:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "CDAE9753-EF8D-4B15-A73C-0EF56FE6C78C"
},
{
"criteria": "cpe:2.3:o:paloaltonetworks:pan-os:9.0.17:h1:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "2A142EE1-E516-4582-9A7E-6E4C74FB3991"
},
{
"criteria": "cpe:2.3:o:paloaltonetworks:pan-os:9.0.17:h2:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "5921D6F7-4C59-4DF1-B5DD-5CCA660B2EAF"
},
{
"criteria": "cpe:2.3:o:paloaltonetworks:pan-os:9.0.17:h3:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "ACF6B9D6-0C48-48FD-8B5A-D0612B660212"
}
],
"operator": "OR"
}
]
}
],
"sourceIdentifier": "psirt@paloaltonetworks.com"
}