CVE-2024-5921: GlobalProtect App: Insufficient Certificate Validation Leads to Privilege Escalation

6.0 CVSS

Description

An insufficient certification validation issue in the Palo Alto Networks GlobalProtect app enables attackers to connect the GlobalProtect app to arbitrary servers. This can enable a local non-administrative operating system user or an attacker on the same subnet to install malicious root certificates on the endpoint and subsequently install malicious software signed by the malicious root certificates on that endpoint.

GlobalProtect App for Android is under evaluation. Please subscribe to our RSS feed https://security.paloaltonetworks.com/rss.xml to be alerted to new updates to this and other advisories.

Classification

CVE ID: CVE-2024-5921

CVSS Base Severity: MEDIUM

CVSS Base Score: 6.0

Affected Products

Vendor: Palo Alto Networks

Product: GlobalProtect App

Exploit Prediction Scoring System (EPSS)

EPSS Score: 0.05% (probability of being exploited)

EPSS Percentile: 17.81% (scored less or equal to compared to others)

EPSS Date: 2025-02-03 (when was this score calculated)

References

https://security.paloaltonetworks.com/CVE-2024-5921
https://blog.amberwolf.com/blog/2024/november/palo-alto-globalprotect---code-execution-and-privilege-escalation-via-malicious-vpn-server-cve-2024-5921/
https://github.com/AmberWolfCyber/NachoVPN

Timeline