An improper certificate validation vulnerability in Palo Alto Networks PAN-OS software enables an authorized user with a specially crafted client certificate to connect to an impacted GlobalProtect portal or GlobalProtect gateway as a different legitimate user. This attack is possible only if you "Allow Authentication with User Credentials OR Client Certificate."
Product Status
Versions
Affected
Unaffected
Cloud NGFW
None
All
PAN-OS 11.2
None
All
PAN-OS 11.1
None
All
PAN-OS 11.0
< 11.0.3
>= 11.0.3
PAN-OS 10.2
< 10.2.4-h5
>= 10.2.4-h5
PAN-OS 10.1
< 10.1.11
>= 10.1.11
Prisma Access
None
All
Required Configuration for Exposure
This issue impacts only firewalls on which you configured a GlobalProtect portal or GlobalProtect gateway to use Client Certificate Authentication and you set the "Allow Authentication with User Credentials OR Client Certificate" option to "Yes".
You can verify whether you configured GlobalProtect portal or gateway by checking for entries in your firewall web interface (Network → GlobalProtect → Portals or Network → GlobalProtect → Gateways).
If you do have GlobalProtect portals or gateways in your configuration, then you can verify whether you configured Client Certificate Authentication on these portals and gateways by checking your firewall web interface (Network → GlobalProtect → Portals → (portal-config) → Authentication or Network → GlobalProtect → Gateways → (gateway-config) → Authentication).
This issue is fixed in PAN-OS 10.1.11, PAN-OS 10.2.4-h5, PAN-OS 10.2.5, PAN-OS 11.0.3, and all later PAN-OS versions.
Workarounds and Mitigations
You can mitigate this issue by setting the "Allow Authentication with User Credentials OR Client Certificate" option to "No." Additional information is available here: