« Volver al listado

CVE-2024-0010

Estado: AnalizadaMedia (6.1)—

A reflected cross-site scripting (XSS) vulnerability in the GlobalProtect portal feature of Palo Alto Networks PAN-OS software enables execution of malicious JavaScript (in the context of a user’s browser) if a user clicks on a malicious link, allowing phishing attacks that could lead to credential theft.

CVSS

Probabilidad de explotación (EPSS)

EPSS (Exploit Prediction Scoring System, de FIRST) estima la probabilidad de que una vulnerabilidad sea explotada en 30 días. Complementa a CVSS (impacto) y a CISA KEV (explotación confirmada).

Tecnologías afectadas (1)

CWE

Referencias

JSON original (NVD)

Mostrar
{
  "id": "CVE-2024-0010",
  "cveTags": [],
  "metrics": {
    "ssvcV203": [
      {
        "source": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
        "ssvcData": {
          "id": "CVE-2024-0010",
          "role": "CISA Coordinator",
          "options": [
            {
              "exploitation": "none"
            },
            {
              "automatable": "no"
            },
            {
              "technicalImpact": "partial"
            }
          ],
          "version": "2.0.3",
          "timestamp": "2024-02-15T16:39:09.757949Z"
        }
      }
    ],
    "cvssMetricV31": [
      {
        "type": "Secondary",
        "source": "psirt@paloaltonetworks.com",
        "cvssData": {
          "scope": "UNCHANGED",
          "version": "3.1",
          "baseScore": 4.3,
          "attackVector": "NETWORK",
          "baseSeverity": "MEDIUM",
          "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:N",
          "integrityImpact": "LOW",
          "userInteraction": "REQUIRED",
          "attackComplexity": "LOW",
          "availabilityImpact": "NONE",
          "privilegesRequired": "NONE",
          "confidentialityImpact": "NONE"
        },
        "impactScore": 1.4,
        "exploitabilityScore": 2.8
      },
      {
        "type": "Primary",
        "source": "nvd@nist.gov",
        "cvssData": {
          "scope": "CHANGED",
          "version": "3.1",
          "baseScore": 6.1,
          "attackVector": "NETWORK",
          "baseSeverity": "MEDIUM",
          "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N",
          "integrityImpact": "LOW",
          "userInteraction": "REQUIRED",
          "attackComplexity": "LOW",
          "availabilityImpact": "NONE",
          "privilegesRequired": "NONE",
          "confidentialityImpact": "LOW"
        },
        "impactScore": 2.7,
        "exploitabilityScore": 2.8
      }
    ]
  },
  "affected": [
    {
      "source": "psirt@paloaltonetworks.com",
      "affectedData": [
        {
          "vendor": "Palo Alto Networks",
          "product": "PAN-OS",
          "versions": [
            {
              "status": "affected",
              "changes": [
                {
                  "at": "9.0.17-h4",
                  "status": "unaffected"
                }
              ],
              "version": "9.0",
              "lessThan": "9.0.17-h4",
              "versionType": "custom"
            },
            {
              "status": "affected",
              "changes": [
                {
                  "at": "9.1.17",
                  "status": "unaffected"
                }
              ],
              "version": "9.1",
              "lessThan": "9.1.17",
              "versionType": "custom"
            },
            {
              "status": "affected",
              "changes": [
                {
                  "at": "10.1.11-h1",
                  "status": "unaffected"
                }
              ],
              "version": "10.1",
              "lessThan": "10.1.11-h1",
              "versionType": "custom"
            },
            {
              "status": "affected",
              "changes": [
                {
                  "at": "10.1.12",
                  "status": "unaffected"
                }
              ],
              "version": "10.1",
              "lessThan": "10.1.12",
              "versionType": "custom"
            },
            {
              "status": "unaffected",
              "changes": [
                {
                  "at": "11.0.1",
                  "status": "unaffected"
                }
              ],
              "version": "10.2",
              "lessThan": "11.0.1",
              "versionType": "custom"
            },
            {
              "status": "unaffected",
              "changes": [
                {
                  "at": "10.1.10-h1",
                  "status": "unaffected"
                }
              ],
              "version": "11.0",
              "lessThan": "10.1.10-h1",
              "versionType": "custom"
            },
            {
              "status": "unaffected",
              "version": "11.1"
            }
          ],
          "defaultStatus": "unaffected"
        },
        {
          "vendor": "Palo Alto Networks",
          "product": "Prisma Access",
          "versions": [
            {
              "status": "unaffected",
              "version": "All"
            }
          ],
          "defaultStatus": "unaffected"
        },
        {
          "vendor": "Palo Alto Networks",
          "product": "Cloud NGFW",
          "versions": [
            {
              "status": "unaffected",
              "version": "All"
            }
          ],
          "defaultStatus": "unaffected"
        }
      ]
    }
  ],
  "published": "2024-02-14T18:15:47.703",
  "references": [
    {
      "url": "https://security.paloaltonetworks.com/CVE-2024-0010",
      "tags": [
        "Vendor Advisory"
      ],
      "source": "psirt@paloaltonetworks.com"
    },
    {
      "url": "https://security.paloaltonetworks.com/CVE-2024-0010",
      "tags": [
        "Vendor Advisory"
      ],
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    }
  ],
  "vulnStatus": "Analyzed",
  "weaknesses": [
    {
      "type": "Secondary",
      "source": "psirt@paloaltonetworks.com",
      "description": [
        {
          "lang": "en",
          "value": "CWE-79"
        }
      ]
    },
    {
      "type": "Primary",
      "source": "nvd@nist.gov",
      "description": [
        {
          "lang": "en",
          "value": "CWE-79"
        }
      ]
    }
  ],
  "descriptions": [
    {
      "lang": "en",
      "value": "A reflected cross-site scripting (XSS) vulnerability in the GlobalProtect portal feature of Palo Alto Networks PAN-OS software enables execution of malicious JavaScript (in the context of a user’s browser) if a user clicks on a malicious link, allowing phishing attacks that could lead to credential theft."
    },
    {
      "lang": "es",
      "value": "Una vulnerabilidad de Cross-Site Scripting (XSS) reflejado en la función del portal GlobalProtect del software PAN-OS de Palo Alto Networks permite la ejecución de JavaScript malicioso (en el contexto del navegador de un usuario) si un usuario hace clic en un enlace malicioso, lo que permite ataques de phishing que podría provocar el robo de credenciales."
    }
  ],
  "lastModified": "2026-06-17T06:52:35.727",
  "configurations": [
    {
      "nodes": [
        {
          "negate": false,
          "cpeMatch": [
            {
              "criteria": "cpe:2.3:o:paloaltonetworks:pan-os:*:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "77695C8C-9732-4605-A160-A5159BD8B49C",
              "versionEndExcluding": "10.1.11",
              "versionStartIncluding": "10.1.0"
            },
            {
              "criteria": "cpe:2.3:o:paloaltonetworks:pan-os:10.1.11:-:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "F6242E26-AF44-4A19-ADD3-CBB798A862D1"
            }
          ],
          "operator": "OR"
        }
      ]
    },
    {
      "nodes": [
        {
          "negate": false,
          "cpeMatch": [
            {
              "criteria": "cpe:2.3:o:paloaltonetworks:pan-os:*:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "9F9FFBA6-7008-422B-9CF1-E37CA62081EB",
              "versionEndExcluding": "9.1.17",
              "versionStartIncluding": "9.1.0"
            }
          ],
          "operator": "OR"
        }
      ]
    },
    {
      "nodes": [
        {
          "negate": false,
          "cpeMatch": [
            {
              "criteria": "cpe:2.3:o:paloaltonetworks:pan-os:*:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "89A55C5F-8E01-42C4-BE93-D683900C07BE",
              "versionEndExcluding": "9.0.17",
              "versionStartIncluding": "9.0.0"
            },
            {
              "criteria": "cpe:2.3:o:paloaltonetworks:pan-os:9.0.17:-:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "CDAE9753-EF8D-4B15-A73C-0EF56FE6C78C"
            },
            {
              "criteria": "cpe:2.3:o:paloaltonetworks:pan-os:9.0.17:h1:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "2A142EE1-E516-4582-9A7E-6E4C74FB3991"
            },
            {
              "criteria": "cpe:2.3:o:paloaltonetworks:pan-os:9.0.17:h2:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "5921D6F7-4C59-4DF1-B5DD-5CCA660B2EAF"
            },
            {
              "criteria": "cpe:2.3:o:paloaltonetworks:pan-os:9.0.17:h3:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "ACF6B9D6-0C48-48FD-8B5A-D0612B660212"
            }
          ],
          "operator": "OR"
        }
      ]
    }
  ],
  "sourceIdentifier": "psirt@paloaltonetworks.com"
}