#VU58112 Improper access control in Palo Alto PAN-OS - CVE-2021-3062
Published: November 11, 2021
Palo Alto PAN-OS
Palo Alto Networks, Inc.
Description
The vulnerability allows a remote user to gain unauthorized access to otherwise restricted functionality.
The vulnerability exists due to improper access restrictions. A remote user with access to GlobalProtect portals and gateways can connect to the EC2 instance metadata endpoint for VM-Series firewalls hosted on Amazon AWS.
Note, the vulnerability affects PAN-OS deployment on VM-Series.