Known vulnerabilities in GlobalProtect Agent

Software CPE: cpe:2.3:a:palo_alto_networks:globalprotect_agent:*:*:*:*:*:*:*:*
Total vulnerabilities: 17
Public exploits: 1
Known exploited (KEV): 0
Highest CVSSv4 Score: 9.2

Breakdown by Severity Chart

Severity distribution of vulnerabilities affecting GlobalProtect Agent GlobalProtect Agent is affected by 17 known vulnerabilities: 1 high, 1 medium, 15 low Critical High Medium Low

Vulnerabilities (17)

Vulnerability CWE-ID CSH Severity Public Exploit KEV First fixed release Published Bulletins
#VU87517 - Concurrent Execution using Shared Resource with Improper Synchronization ('Race Condition')
CVE-2024-2432
CWE-362 Low
Available
No
5.1.12, 6.0.8, 6.1.2, 6.2.1 14.03.2024 SB2024031410
#VU87516 - Improper Access Control
CVE-2024-2431
CWE-284 Low
No
No
5.1.12, 5.2.13, 6.0.4, 6.1.1 14.03.2024 SB2024031410
#VU77364 - Improper Privilege Management
CVE-2023-0009
CWE-269 Low
No
No
5.2.13, 6.0.5, 6.1.1 15.06.2023 SB2023061519
#VU75047 - Time-of-check Time-of-use (TOCTOU) Race Condition
CVE-2023-0006
CWE-367 Low
No
No
5.2.13, 6.0.4, 6.1.1 12.04.2023 SB2023041263
#VU60487 - Information Exposure Through Log Files
CVE-2022-0021
CWE-532 Low
No
No
5.2.9 09.02.2022 SB2022020929
#VU60486 - Insufficiently Protected Credentials
CVE-2022-0019
CWE-522 Low
No
No
5.1.10, 5.3.2 09.02.2022 SB2022020928
#VU60485 - Exposure of sensitive information to an unauthorized actor
CVE-2022-0018
CWE-200 Medium
No
No
5.1.10, 5.2.9 09.02.2022 SB2022020929
#VU60484 - Improper Link Resolution Before File Access ('Link Following')
CVE-2022-0017
CWE-59 Low
No
No
5.1.10, 5.2.5 09.02.2022 SB2022020929
#VU60483 - Improper Check or Handling of Exceptional Conditions
CVE-2022-0016
CWE-703 Low
No
No
5.2.9 09.02.2022 SB2022020929
#VU57345 - Stack-based buffer overflow
CVE-2021-3057
CWE-121 High
No
No
5.1.9, 5.2.8, 5.3.1 13.10.2021 SB2021101317
#VU52224 - Uncaught Exception
CVE-2021-3038
CWE-248 Low
No
No
5.1.8, 5.2.4 14.04.2021 SB2021041420
#VU28966 - Improper Certificate Validation
CVE-2020-2033
CWE-295 Low
No
No
5.0.10, 5.1.4 11.06.2020 SB2020061107
#VU28965 - Time-of-check Time-of-use (TOCTOU) Race Condition
CVE-2020-2032
CWE-367 Low
No
No
5.0.10, 5.1.4 11.06.2020 SB2020061107
#VU27920 - Cleartext Storage of Sensitive Information
CVE-2020-2004
CWE-312 Low
No
No
5.0.9, 5.1.2 14.05.2020 SB2020051414
#VU26740 - Incorrect Privilege Assignment
CVE-2020-1989
CWE-266 Low
No
No
5.0.8, 5.1.1 09.04.2020 SB2020040907
#VU26739 - Untrusted Search Path
CVE-2020-1988
CWE-426 Low
No
No
4.1.13, 5.0.5 09.04.2020 SB2020040906
#VU26738 - Exposure of sensitive information to an unauthorized actor
CVE-2020-1987
CWE-200 Low
No
No
5.0.9, 5.1.1 09.04.2020 SB2020040905