Description
A vulnerability in how Palo Alto Networks PAN-OS software processes data received from Cloud Identity Engine (CIE) agents enables modification of User-ID groups. This impacts user access to network resources where users may be inappropriately denied or allowed access to resources based on your existing Security Policy rules.
No analysis available yet.
Remediation
Vendor Solution
This issue is fixed in PAN-OS 10.1.11, PAN-OS 10.2.5, PAN-OS 11.0.3, and all later PAN-OS versions.
Tracking
Sign in to view the affected projects.
Advisories
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2024-31972 | A vulnerability in how Palo Alto Networks PAN-OS software processes data received from Cloud Identity Engine (CIE) agents enables modification of User-ID groups. This impacts user access to network resources where users may be inappropriately denied or allowed access to resources based on your existing Security Policy rules. |
References
| Link | Providers |
|---|---|
| https://security.paloaltonetworks.com/CVE-2024-3383 |
|
History
Fri, 24 Jan 2025 15:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Paloaltonetworks
Paloaltonetworks pan-os |
|
| Weaknesses | NVD-CWE-Other | |
| CPEs | cpe:2.3:o:paloaltonetworks:pan-os:*:*:*:*:*:*:*:* | |
| Vendors & Products |
Paloaltonetworks
Paloaltonetworks pan-os |
Status: PUBLISHED
Assigner: palo_alto
Published:
Updated: 2024-08-09T20:22:18.991Z
Reserved: 2024-04-05T17:40:16.359Z
Link: CVE-2024-3383
Updated: 2024-08-01T20:12:06.566Z
Status : Analyzed
Published: 2024-04-10T17:15:57.000
Modified: 2025-01-24T15:29:26.313
Link: CVE-2024-3383
No data.
OpenCVE Enrichment
No data.
Weaknesses
EUVD