An improper certificate validation vulnerability in the Prisma® Access Agent for iOS enables an attacker to perform a man-in-the-middle (MitM) attack to intercept VPN traffic.
The Prisma Access Agent on Windows, macOS, Linux, Android and ChromeOS are not affected.
Attack Parameters
Impact Assessment
CVSS Vector v4.0
Weakness Type (CWE)
Vulnerable Products 2
| Configuration | From (including) | Up to (excluding) |
|---|---|---|
|
Paloaltonetworks Prisma_Access_Agent
cpe:2.3:a:paloaltonetworks:prisma_access_agent:*:*:*:*:*:*:*:*
|
— |
26.2.1
|
|
Apple Iphone_Os
cpe:2.3:o:apple:iphone_os:-:*:*:*:*:*:*:*
|
— | — |