CVE-2024-0010
Status: AnalyzedMedium (6.1)—
A reflected cross-site scripting (XSS) vulnerability in the GlobalProtect portal feature of Palo Alto Networks PAN-OS software enables execution of malicious JavaScript (in the context of a user’s browser) if a user clicks on a malicious link, allowing phishing attacks that could lead to credential theft.
CVSS
- Version: 3.1
- Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N
- Base score: 6.1
Exploitation probability (EPSS)
- Probability of exploitation in the next 30 days: 0.51%
- Percentile among all scored CVEs: 42
- Score date: 10/7/2026
EPSS (Exploit Prediction Scoring System, FIRST) estimates how likely a vulnerability is to be exploited in the wild within 30 days. It complements CVSS (impact) and CISA KEV (confirmed exploitation).
Affected technologies (1)
CWEs
- CWE-79
- CWE-79
References
Raw JSON (NVD)
Show
{
"id": "CVE-2024-0010",
"cveTags": [],
"metrics": {
"ssvcV203": [
{
"source": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
"ssvcData": {
"id": "CVE-2024-0010",
"role": "CISA Coordinator",
"options": [
{
"exploitation": "none"
},
{
"automatable": "no"
},
{
"technicalImpact": "partial"
}
],
"version": "2.0.3",
"timestamp": "2024-02-15T16:39:09.757949Z"
}
}
],
"cvssMetricV31": [
{
"type": "Secondary",
"source": "psirt@paloaltonetworks.com",
"cvssData": {
"scope": "UNCHANGED",
"version": "3.1",
"baseScore": 4.3,
"attackVector": "NETWORK",
"baseSeverity": "MEDIUM",
"vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:N",
"integrityImpact": "LOW",
"userInteraction": "REQUIRED",
"attackComplexity": "LOW",
"availabilityImpact": "NONE",
"privilegesRequired": "NONE",
"confidentialityImpact": "NONE"
},
"impactScore": 1.4,
"exploitabilityScore": 2.8
},
{
"type": "Primary",
"source": "nvd@nist.gov",
"cvssData": {
"scope": "CHANGED",
"version": "3.1",
"baseScore": 6.1,
"attackVector": "NETWORK",
"baseSeverity": "MEDIUM",
"vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N",
"integrityImpact": "LOW",
"userInteraction": "REQUIRED",
"attackComplexity": "LOW",
"availabilityImpact": "NONE",
"privilegesRequired": "NONE",
"confidentialityImpact": "LOW"
},
"impactScore": 2.7,
"exploitabilityScore": 2.8
}
]
},
"affected": [
{
"source": "psirt@paloaltonetworks.com",
"affectedData": [
{
"vendor": "Palo Alto Networks",
"product": "PAN-OS",
"versions": [
{
"status": "affected",
"changes": [
{
"at": "9.0.17-h4",
"status": "unaffected"
}
],
"version": "9.0",
"lessThan": "9.0.17-h4",
"versionType": "custom"
},
{
"status": "affected",
"changes": [
{
"at": "9.1.17",
"status": "unaffected"
}
],
"version": "9.1",
"lessThan": "9.1.17",
"versionType": "custom"
},
{
"status": "affected",
"changes": [
{
"at": "10.1.11-h1",
"status": "unaffected"
}
],
"version": "10.1",
"lessThan": "10.1.11-h1",
"versionType": "custom"
},
{
"status": "affected",
"changes": [
{
"at": "10.1.12",
"status": "unaffected"
}
],
"version": "10.1",
"lessThan": "10.1.12",
"versionType": "custom"
},
{
"status": "unaffected",
"changes": [
{
"at": "11.0.1",
"status": "unaffected"
}
],
"version": "10.2",
"lessThan": "11.0.1",
"versionType": "custom"
},
{
"status": "unaffected",
"changes": [
{
"at": "10.1.10-h1",
"status": "unaffected"
}
],
"version": "11.0",
"lessThan": "10.1.10-h1",
"versionType": "custom"
},
{
"status": "unaffected",
"version": "11.1"
}
],
"defaultStatus": "unaffected"
},
{
"vendor": "Palo Alto Networks",
"product": "Prisma Access",
"versions": [
{
"status": "unaffected",
"version": "All"
}
],
"defaultStatus": "unaffected"
},
{
"vendor": "Palo Alto Networks",
"product": "Cloud NGFW",
"versions": [
{
"status": "unaffected",
"version": "All"
}
],
"defaultStatus": "unaffected"
}
]
}
],
"published": "2024-02-14T18:15:47.703",
"references": [
{
"url": "https://security.paloaltonetworks.com/CVE-2024-0010",
"tags": [
"Vendor Advisory"
],
"source": "psirt@paloaltonetworks.com"
},
{
"url": "https://security.paloaltonetworks.com/CVE-2024-0010",
"tags": [
"Vendor Advisory"
],
"source": "af854a3a-2127-422b-91ae-364da2661108"
}
],
"vulnStatus": "Analyzed",
"weaknesses": [
{
"type": "Secondary",
"source": "psirt@paloaltonetworks.com",
"description": [
{
"lang": "en",
"value": "CWE-79"
}
]
},
{
"type": "Primary",
"source": "nvd@nist.gov",
"description": [
{
"lang": "en",
"value": "CWE-79"
}
]
}
],
"descriptions": [
{
"lang": "en",
"value": "A reflected cross-site scripting (XSS) vulnerability in the GlobalProtect portal feature of Palo Alto Networks PAN-OS software enables execution of malicious JavaScript (in the context of a user’s browser) if a user clicks on a malicious link, allowing phishing attacks that could lead to credential theft."
},
{
"lang": "es",
"value": "Una vulnerabilidad de Cross-Site Scripting (XSS) reflejado en la función del portal GlobalProtect del software PAN-OS de Palo Alto Networks permite la ejecución de JavaScript malicioso (en el contexto del navegador de un usuario) si un usuario hace clic en un enlace malicioso, lo que permite ataques de phishing que podría provocar el robo de credenciales."
}
],
"lastModified": "2026-06-17T06:52:35.727",
"configurations": [
{
"nodes": [
{
"negate": false,
"cpeMatch": [
{
"criteria": "cpe:2.3:o:paloaltonetworks:pan-os:*:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "77695C8C-9732-4605-A160-A5159BD8B49C",
"versionEndExcluding": "10.1.11",
"versionStartIncluding": "10.1.0"
},
{
"criteria": "cpe:2.3:o:paloaltonetworks:pan-os:10.1.11:-:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "F6242E26-AF44-4A19-ADD3-CBB798A862D1"
}
],
"operator": "OR"
}
]
},
{
"nodes": [
{
"negate": false,
"cpeMatch": [
{
"criteria": "cpe:2.3:o:paloaltonetworks:pan-os:*:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "9F9FFBA6-7008-422B-9CF1-E37CA62081EB",
"versionEndExcluding": "9.1.17",
"versionStartIncluding": "9.1.0"
}
],
"operator": "OR"
}
]
},
{
"nodes": [
{
"negate": false,
"cpeMatch": [
{
"criteria": "cpe:2.3:o:paloaltonetworks:pan-os:*:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "89A55C5F-8E01-42C4-BE93-D683900C07BE",
"versionEndExcluding": "9.0.17",
"versionStartIncluding": "9.0.0"
},
{
"criteria": "cpe:2.3:o:paloaltonetworks:pan-os:9.0.17:-:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "CDAE9753-EF8D-4B15-A73C-0EF56FE6C78C"
},
{
"criteria": "cpe:2.3:o:paloaltonetworks:pan-os:9.0.17:h1:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "2A142EE1-E516-4582-9A7E-6E4C74FB3991"
},
{
"criteria": "cpe:2.3:o:paloaltonetworks:pan-os:9.0.17:h2:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "5921D6F7-4C59-4DF1-B5DD-5CCA660B2EAF"
},
{
"criteria": "cpe:2.3:o:paloaltonetworks:pan-os:9.0.17:h3:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "ACF6B9D6-0C48-48FD-8B5A-D0612B660212"
}
],
"operator": "OR"
}
]
}
],
"sourceIdentifier": "psirt@paloaltonetworks.com"
}