CVE-2021-3038

A denial-of-service (DoS) vulnerability in Palo Alto Networks GlobalProtect app on Windows systems allows a limited Windows user to send specifically-crafted input to the GlobalProtect app that results in a Windows blue screen of death (BSOD) error. This issue impacts: GlobalProtect app 5.1 versions earlier than GlobalProtect app 5.1.8; GlobalProtect app 5.2 versions earlier than GlobalProtect app 5.2.4.
References
Configurations

Configuration 1 (hide)

OR cpe:2.3:a:paloaltonetworks:globalprotect:*:*:*:*:*:windows:*:*
cpe:2.3:a:paloaltonetworks:globalprotect:*:*:*:*:*:windows:*:*

History

27 Oct 2022, 12:43

Type Values Removed Values Added
CWE CWE-20 NVD-CWE-noinfo

24 Apr 2021, 02:58

Type Values Removed Values Added
CWE CWE-20
CVSS v2 : unknown
v3 : 5.5
v2 : 4.9
v3 : 5.5
References (MISC) https://security.paloaltonetworks.com/CVE-2021-3038 - (MISC) https://security.paloaltonetworks.com/CVE-2021-3038 - Vendor Advisory
CPE cpe:2.3:a:paloaltonetworks:globalprotect:*:*:*:*:*:windows:*:*

20 Apr 2021, 04:15

Type Values Removed Values Added
New CVE

Information

Published : 2021-04-20 04:15

Updated : 2023-12-10 13:55


NVD link : CVE-2021-3038

Mitre link : CVE-2021-3038

CVE.ORG link : CVE-2021-3038


JSON object : View

Products Affected

paloaltonetworks

  • globalprotect
CWE
NVD-CWE-noinfo CWE-20

Improper Input Validation

CWE-248

Uncaught Exception