Skip to content

globalprotect

GlobalProtect OS Command Injection Vulnerability

PANW has published OS Command Injection Vulnerability in GlobalProtect, highest possible severity 10 – Critical. https://security.paloaltonetworks.com/CVE-2024-3400 At the time of publishing, no fixes were available, but if firewall was configured according best practises, mitigation was out of the box. How? Let’s go into details. Palo Alto Networks firewall has three types of security policies: Every… Read More »GlobalProtect OS Command Injection Vulnerability

GlobalProtect Pre-logon

GlobalProtect Pre-logon is a remote connection method based on machine certificate authentication. Practical use cases to deploy Pre-logon are: Configuration steps in detail are elaborated here: https://knowledgebase.paloaltonetworks.com/KCSArticleDetail?id=kA10g000000ClEYCA0 Be aware of mandatory conditions to make it running, one of the following three must exist: Portal contains ‘certificate profile’ but ‘no’ auth cookiesPortal does ‘not’ contain ‘certificate… Read More »GlobalProtect Pre-logon