Vulnerability Intelligence Report
PAN-OS: Memory Corruption Vulnerability in GlobalProtect Portal and Gateway Interfaces
CVE-2021-3064
A memory corruption vulnerability exists in Palo Alto Networks GlobalProtect portal and gateway interfaces that enables an unauthenticated network-based attacker to disrupt system processes and potentially execute arbitrary code with root privileges. The attacker must have network access to the GlobalProtect interface to exploit this issue. This issue impacts PAN-OS 8.1 versions earlier than PAN-OS 8.1.17. Prisma Access customers are not impacted by this issue.
No Active Exploit Signals
CVSS Base Score
9.8
CRITICAL
Exploitability:3.9
Impact Score:5.9
EPSS Probability:19.09%
Executive Threat Verdict
Evaluating...
Evaluating Threat Landscape...
Assessing known weaponization, exploitation telemetry, and federal advisories.
Attack Surface
—
Authentication
—
Weaponization
—
SSVC Action
—
Weaknesses (CWE)
CWE-121 ↗CWE-121 Stack-based Buffer Overflow
Affected Products & Versions
| Vendor | Product | Affected Versions |
|---|---|---|
| Palo Alto Networks | PAN-OS | 9.0.* (unaffected), 9.1.* (unaffected), 10.0.* (unaffected), 10.1.* (unaffected), 8.1 < 8.1.17 (affected) |
| Palo Alto Networks | Prisma Access | 2.2 all (unaffected), 2.1 all (unaffected) |
References & Technical Advisories
No reference links found.
Threat Intelligence Signals
EPSS Score
19.087%
GitHub Advisory
Identity & Timeline
| Status | PUBLISHED |
| Assigning Authority | Palo Alto Networks, Inc. · Vendor · USA |
| Reserved | 2021-01-06T00:00:00 |
| Published | 2021-11-10T17:10:31 |
| Patch Date | 2021-11-10 |
| Last Updated | 2024-09-17T03:28:39 |
Community Chatter & Buzz