CVE-2024-3388
Estado: AnalizadaMedia (5)—
A vulnerability in the GlobalProtect Gateway in Palo Alto Networks PAN-OS software enables an authenticated attacker to impersonate another user and send network packets to internal assets. However, this vulnerability does not allow the attacker to receive response packets from those internal assets.
CVSS
- Versión: 3.1
- Vector: CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:N/I:L/A:N
- Puntuación base: 5
Probabilidad de explotación (EPSS)
- Probabilidad de explotación en los próximos 30 días: 0.35%
- Percentil entre todas las CVEs puntuadas: 26
- Fecha de la puntuación: 6/10/2026
EPSS (Exploit Prediction Scoring System, de FIRST) estima la probabilidad de que una vulnerabilidad sea explotada en 30 días. Complementa a CVSS (impacto) y a CISA KEV (explotación confirmada).
Tecnologías afectadas (2)
CWE
- CWE-269, CWE-863
- CWE-269, CWE-863
Referencias
JSON original (NVD)
Mostrar
{
"id": "CVE-2024-3388",
"cveTags": [],
"metrics": {
"ssvcV203": [
{
"source": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
"ssvcData": {
"id": "CVE-2024-3388",
"role": "CISA Coordinator",
"options": [
{
"exploitation": "none"
},
{
"automatable": "no"
},
{
"technicalImpact": "partial"
}
],
"version": "2.0.3",
"timestamp": "2024-04-15T14:39:04.465851Z"
}
}
],
"cvssMetricV31": [
{
"type": "Secondary",
"source": "psirt@paloaltonetworks.com",
"cvssData": {
"scope": "CHANGED",
"version": "3.1",
"baseScore": 4.1,
"attackVector": "NETWORK",
"baseSeverity": "MEDIUM",
"vectorString": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:N/I:L/A:N",
"integrityImpact": "LOW",
"userInteraction": "REQUIRED",
"attackComplexity": "LOW",
"availabilityImpact": "NONE",
"privilegesRequired": "LOW",
"confidentialityImpact": "NONE"
},
"impactScore": 1.4,
"exploitabilityScore": 2.3
},
{
"type": "Primary",
"source": "nvd@nist.gov",
"cvssData": {
"scope": "CHANGED",
"version": "3.1",
"baseScore": 5,
"attackVector": "NETWORK",
"baseSeverity": "MEDIUM",
"vectorString": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:N/I:L/A:N",
"integrityImpact": "LOW",
"userInteraction": "NONE",
"attackComplexity": "LOW",
"availabilityImpact": "NONE",
"privilegesRequired": "LOW",
"confidentialityImpact": "NONE"
},
"impactScore": 1.4,
"exploitabilityScore": 3.1
}
]
},
"affected": [
{
"source": "psirt@paloaltonetworks.com",
"affectedData": [
{
"vendor": "Palo Alto Networks",
"product": "PAN-OS",
"versions": [
{
"status": "affected",
"changes": [
{
"at": "8.1.26",
"status": "unaffected"
}
],
"version": "8.1.0",
"lessThan": "8.1.26",
"versionType": "custom"
},
{
"status": "affected",
"changes": [
{
"at": "9.0.17-h4",
"status": "unaffected"
}
],
"version": "9.0.0",
"lessThan": "9.0.17-h4",
"versionType": "custom"
},
{
"status": "affected",
"changes": [
{
"at": "9.1.17",
"status": "unaffected"
}
],
"version": "9.1.0",
"lessThan": "9.1.17",
"versionType": "custom"
},
{
"status": "affected",
"changes": [
{
"at": "10.1.11-h4",
"status": "unaffected"
}
],
"version": "10.1.0",
"lessThan": "10.1.11-h4",
"versionType": "custom"
},
{
"status": "affected",
"changes": [
{
"at": "10.2.7-h3",
"status": "unaffected"
}
],
"version": "10.2.0",
"lessThan": "10.2.7-h3",
"versionType": "custom"
},
{
"status": "affected",
"changes": [
{
"at": "11.0.3",
"status": "unaffected"
}
],
"version": "11.0.0",
"lessThan": "11.0.3",
"versionType": "custom"
},
{
"status": "unaffected",
"version": "11.1.0"
}
],
"defaultStatus": "unaffected"
},
{
"vendor": "Palo Alto Networks",
"product": "Cloud NGFW",
"versions": [
{
"status": "unaffected",
"version": "All"
}
],
"defaultStatus": "unaffected"
},
{
"vendor": "Palo Alto Networks",
"product": "Prisma Access",
"versions": [
{
"status": "affected",
"changes": [
{
"at": "10.2.4",
"status": "unaffected"
}
],
"version": "10.2",
"lessThan": "10.2.4",
"versionType": "custom"
}
],
"defaultStatus": "unaffected"
}
]
}
],
"published": "2024-04-10T17:15:57.970",
"references": [
{
"url": "https://security.paloaltonetworks.com/CVE-2024-3388",
"tags": [
"Vendor Advisory"
],
"source": "psirt@paloaltonetworks.com"
},
{
"url": "https://security.paloaltonetworks.com/CVE-2024-3388",
"tags": [
"Vendor Advisory"
],
"source": "af854a3a-2127-422b-91ae-364da2661108"
}
],
"vulnStatus": "Analyzed",
"weaknesses": [
{
"type": "Secondary",
"source": "psirt@paloaltonetworks.com",
"description": [
{
"lang": "en",
"value": "CWE-269"
},
{
"lang": "en",
"value": "CWE-863"
}
]
},
{
"type": "Primary",
"source": "nvd@nist.gov",
"description": [
{
"lang": "en",
"value": "CWE-269"
},
{
"lang": "en",
"value": "CWE-863"
}
]
}
],
"descriptions": [
{
"lang": "en",
"value": "A vulnerability in the GlobalProtect Gateway in Palo Alto Networks PAN-OS software enables an authenticated attacker to impersonate another user and send network packets to internal assets. However, this vulnerability does not allow the attacker to receive response packets from those internal assets."
},
{
"lang": "es",
"value": "Una vulnerabilidad en GlobalProtect Gateway del software PAN-OS de Palo Alto Networks permite que un atacante autenticado se haga pasar por otro usuario y envíe paquetes de red a recursos internos. Sin embargo, esta vulnerabilidad no permite que el atacante reciba paquetes de respuesta de esos recursos internos."
}
],
"lastModified": "2026-06-17T07:44:11.063",
"configurations": [
{
"nodes": [
{
"negate": false,
"cpeMatch": [
{
"criteria": "cpe:2.3:o:paloaltonetworks:pan-os:*:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "E37C0550-B96B-4A7F-A330-F2D7F4756D8D",
"versionEndExcluding": "8.1.26",
"versionStartIncluding": "8.1.0"
},
{
"criteria": "cpe:2.3:o:paloaltonetworks:pan-os:*:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "89A55C5F-8E01-42C4-BE93-D683900C07BE",
"versionEndExcluding": "9.0.17",
"versionStartIncluding": "9.0.0"
},
{
"criteria": "cpe:2.3:o:paloaltonetworks:pan-os:*:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "9F9FFBA6-7008-422B-9CF1-E37CA62081EB",
"versionEndExcluding": "9.1.17",
"versionStartIncluding": "9.1.0"
},
{
"criteria": "cpe:2.3:o:paloaltonetworks:pan-os:*:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "77695C8C-9732-4605-A160-A5159BD8B49C",
"versionEndExcluding": "10.1.11",
"versionStartIncluding": "10.1.0"
},
{
"criteria": "cpe:2.3:o:paloaltonetworks:pan-os:*:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "243077CD-5021-4DF3-8AC7-5B14F7FD9710",
"versionEndExcluding": "10.2.7",
"versionStartIncluding": "10.2.0"
},
{
"criteria": "cpe:2.3:o:paloaltonetworks:pan-os:*:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "A6B9B8A6-A4A7-4C14-9D22-50FEF531F15D",
"versionEndExcluding": "11.0.3",
"versionStartIncluding": "11.0.0"
},
{
"criteria": "cpe:2.3:o:paloaltonetworks:pan-os:9.0.17:-:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "CDAE9753-EF8D-4B15-A73C-0EF56FE6C78C"
},
{
"criteria": "cpe:2.3:o:paloaltonetworks:pan-os:9.0.17:h1:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "2A142EE1-E516-4582-9A7E-6E4C74FB3991"
},
{
"criteria": "cpe:2.3:o:paloaltonetworks:pan-os:10.1.11:-:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "F6242E26-AF44-4A19-ADD3-CBB798A862D1"
},
{
"criteria": "cpe:2.3:o:paloaltonetworks:pan-os:10.1.11:h1:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "72EF4202-7A13-4528-B928-CC34B76725B4"
},
{
"criteria": "cpe:2.3:o:paloaltonetworks:pan-os:10.1.11:h3:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "8E58BF5C-037D-45B1-8867-D510EC0F80B9"
},
{
"criteria": "cpe:2.3:o:paloaltonetworks:pan-os:10.2.7:-:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "A8C42D98-CF8F-456B-9D57-80BBDC2C8E74"
},
{
"criteria": "cpe:2.3:o:paloaltonetworks:pan-os:10.2.7:h1:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "B3AAD4BA-22DD-43D3-91F1-8A6F5FBBF029"
}
],
"operator": "OR"
}
]
},
{
"nodes": [
{
"negate": false,
"cpeMatch": [
{
"criteria": "cpe:2.3:a:paloaltonetworks:prisma_access:-:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "FFB6FBC7-DEEB-4571-BCF9-92345A4B614A"
}
],
"operator": "OR"
}
]
}
],
"sourceIdentifier": "psirt@paloaltonetworks.com"
}