Palo Alto GlobalProtect SSL VPN远程命令执行漏洞

- AV AC AU C I A
发布: 2025-04-13
修订: 2025-04-13

In this article, we would like to talk about the vulnerability on Palo Alto SSL VPN. Palo Alto calls their SSL VPN product line as GlobalProtect. You can easily identify the GlobalPortect service via the 302 redirection to ``` /global-protect/login.esp ``` on web root! About the vulnerability, we accidentally discovered it during our Red Team assessment services . At first, we thought this is a 0day. However, we failed reproducing on the remote server which is the latest version of GlobalProtect. So we began to suspect if this is a known vulnerability. We searched all over the Internet, but we could not find anything. There is no public RCE exploit before[1], no official advisory contains anything similar and no CVE. So we believe this must be a silent-fix 1-day! [1] There are some exploit about the Pan-OS management interface before such as the [CVE-2017-15944](https://www.exploit-db.com/exploits/43342) and the excellent [Troppers16...

0%
暂无可用Exp或PoC
当前有0条受影响产品信息