Loading
Generated remediation guidance and an executive summary. No account required.
An improper certificate validation vulnerability in Palo Alto Networks PAN-OS software enables an authorized user with a specially crafted client certificate to connect to an impacted GlobalProtect portal or GlobalProtect gateway as a different legitimate user. This attack is possible only if you "Allow Authentication with User Credentials OR Client Certificate."
Use CWE-295, Paloaltonetworks vendor hub and Pan-Os product page to widen CVE-2024-5918 into its surrounding weakness, vendor, and product context.
Compare it with CVE-2024-0012, CVE-2025-0108 and CVE-2024-3393 for nearby disclosures in the same product family.