<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Palo Alto's stance on CVE-2024-3661 in General Topics</title>
    <link>https://live.paloaltonetworks.com/t5/general-topics/palo-alto-s-stance-on-cve-2024-3661/m-p/586985#M117133</link>
    <description>&lt;P&gt;Hi &lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/235054"&gt;@JamesH1318&lt;/a&gt; ,&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;The response was just released.&amp;nbsp; &lt;A href="https://security.paloaltonetworks.com/CVE-2024-3661" target="_blank"&gt;https://security.paloaltonetworks.com/CVE-2024-3661&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Thanks,&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Tom&lt;/P&gt;</description>
    <pubDate>Thu, 16 May 2024 16:28:30 GMT</pubDate>
    <dc:creator>TomYoung</dc:creator>
    <dc:date>2024-05-16T16:28:30Z</dc:date>
    <item>
      <title>Palo Alto's stance on CVE-2024-3661</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/palo-alto-s-stance-on-cve-2024-3661/m-p/586166#M116992</link>
      <description>&lt;P&gt;Does PA have a response to&amp;nbsp;&lt;STRONG&gt;CVE&lt;/STRONG&gt;&lt;SPAN&gt;-2024-3661 for it's GlobalProtect users?&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Wed, 08 May 2024 12:57:52 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/palo-alto-s-stance-on-cve-2024-3661/m-p/586166#M116992</guid>
      <dc:creator>JamesH1318</dc:creator>
      <dc:date>2024-05-08T12:57:52Z</dc:date>
    </item>
    <item>
      <title>Re: Palo Alto's stance on CVE-2024-3661</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/palo-alto-s-stance-on-cve-2024-3661/m-p/586199#M117000</link>
      <description>&lt;BLOCKQUOTE&gt;&lt;HR /&gt;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/235054"&gt;@JamesH1318&lt;/a&gt;&amp;nbsp;wrote:&lt;BR /&gt;
&lt;P&gt;Does PA have a response to&amp;nbsp;&lt;STRONG&gt;CVE&lt;/STRONG&gt;&lt;SPAN&gt;-2024-3661 for it's GlobalProtect users?&lt;/SPAN&gt;&lt;/P&gt;
&lt;HR /&gt;&lt;/BLOCKQUOTE&gt;
&lt;P&gt;This post is lacking context.&amp;nbsp; This CVE isn't specific to Palo Alto, and according to NIST is a relatively low risk.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="Brandon_Wertz_0-1715181733402.png" style="width: 400px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/59583i061986F7F59727B8/image-size/medium/is-moderation-mode/true?v=v2&amp;amp;px=400" role="button" title="Brandon_Wertz_0-1715181733402.png" alt="Brandon_Wertz_0-1715181733402.png" /&gt;&lt;/span&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Wed, 08 May 2024 15:22:46 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/palo-alto-s-stance-on-cve-2024-3661/m-p/586199#M117000</guid>
      <dc:creator>Brandon_Wertz</dc:creator>
      <dc:date>2024-05-08T15:22:46Z</dc:date>
    </item>
    <item>
      <title>Re: Palo Alto's stance on CVE-2024-3661</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/palo-alto-s-stance-on-cve-2024-3661/m-p/586241#M117008</link>
      <description>&lt;P&gt;I'm not sure how 7.6 High equates to "relatively low."&amp;nbsp; It's true that it's not Palo Alto specific but it does affect GlobalProtect. I would expect Palo Alto to do some research and determine the best mitigation steps, if any, for GP users.&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Thu, 09 May 2024 02:26:29 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/palo-alto-s-stance-on-cve-2024-3661/m-p/586241#M117008</guid>
      <dc:creator>JamesH1318</dc:creator>
      <dc:date>2024-05-09T02:26:29Z</dc:date>
    </item>
    <item>
      <title>Re: Palo Alto's stance on CVE-2024-3661</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/palo-alto-s-stance-on-cve-2024-3661/m-p/586319#M117019</link>
      <description>&lt;P&gt;I'd be interested in mitigation options as well. One idea I had would be push multiple /2 routes instead of the 0.0.0.0/0 route to my GP clients, obviously that isn't full proof. I could also add /32 routes to my high value hosts so I know that traffic will route via the VPN.&lt;/P&gt;</description>
      <pubDate>Thu, 09 May 2024 19:29:07 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/palo-alto-s-stance-on-cve-2024-3661/m-p/586319#M117019</guid>
      <dc:creator>KirkHartstrom</dc:creator>
      <dc:date>2024-05-09T19:29:07Z</dc:date>
    </item>
    <item>
      <title>Re: Palo Alto's stance on CVE-2024-3661</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/palo-alto-s-stance-on-cve-2024-3661/m-p/586325#M117020</link>
      <description>&lt;P&gt;Hi &lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/235054"&gt;@JamesH1318&lt;/a&gt; ,&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Thank you for your timely post!&amp;nbsp; I do not work for PANW, but I imagine they are working on a response.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;CVE-2024-3661, a.k.a TunnelVision, is very similar to TunnelCrack, &lt;A href="https://security.paloaltonetworks.com/PAN-SA-2023-0004" target="_blank"&gt;https://security.paloaltonetworks.com/PAN-SA-2023-0004&lt;/A&gt;.&amp;nbsp; If you scroll down to the Solution section of the URL, you will see a PANW article detailing the mitigation.&amp;nbsp; In this case, I think checking the box "No direct access to local network" should mitigate this CVE, much like it did the LocalNet attack portion of Tunnel Crack.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Hopefully, we will hear an official word soon.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Thanks,&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Tom&lt;/P&gt;</description>
      <pubDate>Thu, 09 May 2024 20:51:35 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/palo-alto-s-stance-on-cve-2024-3661/m-p/586325#M117020</guid>
      <dc:creator>TomYoung</dc:creator>
      <dc:date>2024-05-09T20:51:35Z</dc:date>
    </item>
    <item>
      <title>Re: Palo Alto's stance on CVE-2024-3661</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/palo-alto-s-stance-on-cve-2024-3661/m-p/586327#M117021</link>
      <description>&lt;P&gt;I contacted support and them/PSIRT says they are not affected by this CVE. we'll see if they post something.&lt;/P&gt;</description>
      <pubDate>Thu, 09 May 2024 20:54:24 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/palo-alto-s-stance-on-cve-2024-3661/m-p/586327#M117021</guid>
      <dc:creator>googol</dc:creator>
      <dc:date>2024-05-09T20:54:24Z</dc:date>
    </item>
    <item>
      <title>Re: Palo Alto's stance on CVE-2024-3661</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/palo-alto-s-stance-on-cve-2024-3661/m-p/586490#M117043</link>
      <description>&lt;P&gt;Thanks. I think it's more than that. I think the only real mitigation is to disable local LAN access AND disable split tunneling. Only then do I believe GP ignores the routing table and sends everything down the tunnel. But, as you said, hopefully, PAN will respond.&lt;/P&gt;</description>
      <pubDate>Mon, 13 May 2024 12:38:15 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/palo-alto-s-stance-on-cve-2024-3661/m-p/586490#M117043</guid>
      <dc:creator>JamesH1318</dc:creator>
      <dc:date>2024-05-13T12:38:15Z</dc:date>
    </item>
    <item>
      <title>Re: Palo Alto's stance on CVE-2024-3661</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/palo-alto-s-stance-on-cve-2024-3661/m-p/586531#M117055</link>
      <description>&lt;P&gt;Hello,&lt;/P&gt;
&lt;P&gt;Since it requires a malicious DHCP server, etc. I would suggest using your phone as a hotspot when need WiFi away from a trusted source.&lt;/P&gt;
&lt;P&gt;Regards,&lt;/P&gt;</description>
      <pubDate>Mon, 13 May 2024 19:54:43 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/palo-alto-s-stance-on-cve-2024-3661/m-p/586531#M117055</guid>
      <dc:creator>OtakarKlier</dc:creator>
      <dc:date>2024-05-13T19:54:43Z</dc:date>
    </item>
    <item>
      <title>Re: Palo Alto's stance on CVE-2024-3661</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/palo-alto-s-stance-on-cve-2024-3661/m-p/586985#M117133</link>
      <description>&lt;P&gt;Hi &lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/235054"&gt;@JamesH1318&lt;/a&gt; ,&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;The response was just released.&amp;nbsp; &lt;A href="https://security.paloaltonetworks.com/CVE-2024-3661" target="_blank"&gt;https://security.paloaltonetworks.com/CVE-2024-3661&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Thanks,&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Tom&lt;/P&gt;</description>
      <pubDate>Thu, 16 May 2024 16:28:30 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/palo-alto-s-stance-on-cve-2024-3661/m-p/586985#M117133</guid>
      <dc:creator>TomYoung</dc:creator>
      <dc:date>2024-05-16T16:28:30Z</dc:date>
    </item>
    <item>
      <title>Re: Palo Alto's stance on CVE-2024-3661</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/palo-alto-s-stance-on-cve-2024-3661/m-p/586998#M117135</link>
      <description>&lt;P&gt;Here is the CVE advisory published today -&amp;nbsp;&lt;A href="https://security.paloaltonetworks.com/CVE-2024-3661" target="_blank"&gt;https://security.paloaltonetworks.com/CVE-2024-3661&lt;/A&gt;&lt;/P&gt;</description>
      <pubDate>Thu, 16 May 2024 17:43:52 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/palo-alto-s-stance-on-cve-2024-3661/m-p/586998#M117135</guid>
      <dc:creator>trjohnson</dc:creator>
      <dc:date>2024-05-16T17:43:52Z</dc:date>
    </item>
  </channel>
</rss>

