GlobalProtect Agent 4.1.0 for Windows and GlobalProtect Agent 4.1.10 and earlier for macOS may allow a local authenticated attacker who has compromised the end-user account and gained the ability to inspect memory, to access authentication and/or session tokens and replay them to spoof the VPN session and gain access as the user.
Metrics
Affected Vendors & Products
References
History
No history.
MITRE
Status: PUBLISHED
Assigner: palo_alto
Published: 2019-04-09T21:04:01.397792Z
Updated: 2024-09-16T19:21:01.439Z
Reserved: 2018-12-06T00:00:00
Link: CVE-2019-1573
Vulnrichment
No data.
NVD
Status : Analyzed
Published: 2019-04-09T22:29:00.877
Modified: 2021-09-14T12:14:39.193
Link: CVE-2019-1573
Redhat
No data.