CVE-2020-1989 PUBLISHED CVSS 7 HIGH

An incorrect privilege assignment vulnerability when writing application-specific files in the Palo Alto Networks Global Protect Agent for Linux on ARM platform allows a local authenticated user to gain root privileges on the system. This issue affects Palo Alto Networks Global Protect Agent for Linux 5.0 versions before 5.0.8; 5.1 versions before 5.1.1.

EPSS 0.11% · 29.1th percentile

Risk Scores

CVSS v3.1
7
CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H
EPSS Score
0.11%
29.1th percentile

Affected Products

VendorProductVersions
Palo Alto NetworksGlobal Protect Agent5.0, 5.1
paloaltonetworksglobalprotect5.0, 5.1

Timeline

References

Open in Interactive Console →