Lucene search

K
cvePalo_altoCVE-2022-0021
HistoryFeb 10, 2022 - 6:15 p.m.

CVE-2022-0021

2022-02-1018:15:08
CWE-532
palo_alto
web.nvd.nist.gov
44
1
cve-2022-0021
information exposure
log file vulnerability
palo alto networks
globalprotect
windows
connect before logon
nvd

CVSS2

1.9

Attack Vector

LOCAL

Attack Complexity

MEDIUM

Authentication

NONE

Confidentiality Impact

PARTIAL

Integrity Impact

NONE

Availability Impact

NONE

AV:L/AC:M/Au:N/C:P/I:N/A:N

CVSS3

5.5

Attack Vector

LOCAL

Attack Complexity

LOW

Privileges Required

LOW

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

HIGH

Integrity Impact

NONE

Availability Impact

NONE

CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N

AI Score

5.3

Confidence

High

EPSS

0

Percentile

12.6%

An information exposure through log file vulnerability exists in the Palo Alto Networks GlobalProtect app on Windows that logs the cleartext credentials of the connecting GlobalProtect user when authenticating using Connect Before Logon feature. This issue impacts GlobalProtect App 5.2 versions earlier than 5.2.9 on Windows. This issue does not affect the GlobalProtect app on other platforms.

Affected configurations

Nvd
Vulners
Node
paloaltonetworksglobalprotectRange5.25.2.9
AND
microsoftwindowsMatch-
VendorProductVersionCPE
paloaltonetworksglobalprotect*cpe:2.3:a:paloaltonetworks:globalprotect:*:*:*:*:*:*:*:*
microsoftwindows-cpe:2.3:o:microsoft:windows:-:*:*:*:*:*:*:*

CNA Affected

[
  {
    "platforms": [
      "Windows"
    ],
    "product": "GlobalProtect App",
    "vendor": "Palo Alto Networks",
    "versions": [
      {
        "changes": [
          {
            "at": "5.2.9",
            "status": "unaffected"
          }
        ],
        "lessThan": "5.2.9",
        "status": "affected",
        "version": "5.2",
        "versionType": "custom"
      }
    ]
  },
  {
    "product": "GlobalProtect App",
    "vendor": "Palo Alto Networks",
    "versions": [
      {
        "status": "unaffected",
        "version": "5.1.*"
      },
      {
        "status": "unaffected",
        "version": "5.3.*"
      }
    ]
  }
]

Social References

More

CVSS2

1.9

Attack Vector

LOCAL

Attack Complexity

MEDIUM

Authentication

NONE

Confidentiality Impact

PARTIAL

Integrity Impact

NONE

Availability Impact

NONE

AV:L/AC:M/Au:N/C:P/I:N/A:N

CVSS3

5.5

Attack Vector

LOCAL

Attack Complexity

LOW

Privileges Required

LOW

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

HIGH

Integrity Impact

NONE

Availability Impact

NONE

CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N

AI Score

5.3

Confidence

High

EPSS

0

Percentile

12.6%

Related for CVE-2022-0021