VDB
CVE-2019-1573
CVE-2019-1573
PUBLISHED
CVSS 2.5 LOW
GlobalProtect Agent 4.1.0 for Windows and GlobalProtect Agent 4.1.10 and earlier for macOS may allow a local authenticated attacker who has compromised the end-user account and gained the ability to inspect memory, to access authentication and/or session tokens and replay them to spoof the VPN session and gain access as the user.
EPSS 0.23% · 45.8th percentile
Risk Scores
CVSS 3.1
2.5
CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:L/I:N/A:N
EPSS Score
0.23%
45.8th percentile
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Palo Alto Networks | GlobalProtect Agent | 4.1, 4.1.11 |
| paloaltonetworks | globalprotect | 0, 0 |
Timeline
- Apr 9, 2019 CVE Published
- Apr 14, 2021 EPSS Score
- Jun 23, 2021 EPSS Score
- Aug 24, 2021 EPSS Score
- Oct 26, 2021 EPSS Score
- Jan 6, 2022 EPSS Score
- Feb 4, 2022 EPSS Score
- Feb 28, 2022 EPSS Score
- Apr 1, 2022 EPSS Score
- May 1, 2022 EPSS Score
- Jul 3, 2022 EPSS Score
- Sep 4, 2022 EPSS Score
References
- VU#192371 third-party-advisory
- 107868 vdb
- https://psirt.global.sonicwall.com/vuln-detail/SNWLID-2019-0005 url
- https://www.broadcom.com/support/fibre-channel-networking/security-advisories/brocade-security-advisory-2019-783 url
- https://security.paloaltonetworks.com/CVE-2019-1573 url
- https://nvd.nist.gov/vuln/detail/CVE-2019-1573 advisory