• Creation
  • Validation
  • Communication & fix
  • Disclosure

jcdecaux.be / Palo Alto (Global-network) instance is outdated

Deleted user reported 2021-11-14

The following Palo Alto (Global-network) is publicly accessible and looks out-dated :

https://194.78.59.26/global-protect/login.esp

https://195.198.69.184/global-protect/login.esp

https://195.156.61.126/global-protect/login.esp

It is critical to update to a safe version as soon as possible since multiple CVEs could allow remote attackers to DoS or achieve RCE (Remote code execution) on the device.

The CVE-2021-3064 prevention reports are identified and dispatched with the help of https://twitter.com/HaboubiAnis

Reference:

IP:
194.78.59.26
Port:
443
Detected protocol:
https
Found PAN-OS web frontend
Last update: 6/2020
Version: 8.1.15-h3
Affected by CVE-2021-3064
Found by PaloAltoPlugin 2021-11-14
IP:
194.78.59.26
Port:
443
Detected protocol:
https
Found PAN-OS web frontend
Last update: 6/2020
Version: 8.1.15-h3
Affected by CVE-2021-3064
Found by PaloAltoPlugin 2021-11-17
IP:
194.78.59.26
Port:
443
Detected protocol:
https
Found PAN-OS web frontend
Last update: 6/2020
Version: 8.1.15-h3
Affected by CVE-2021-3064
Found by PaloAltoPlugin 2021-11-18
Report created by deleted-user  2021-11-14
Report approved by BloodyShell  2021-11-14
New PDF report generated by system 2021-11-14
Report dispatched to ...@... by system 2021-11-14
Report dispatched to ...@... by system 2021-11-14
system commented 2021-11-22: approved shows in report

bip! I'm a LeakIX probe.

This issue looks like it has been resolved!

New PDF report generated by system 2021-11-22
Report comment dispatched to zythop by system 2021-11-22
Report comment dispatched to info@jcdecaux.be by system 2021-11-22
Report comment dispatched to vulnerabilitydisclosure@ccb.belgium.be by system 2021-11-22
BloodyShell commented 2021-11-22: approved shows in report

Still vulnerable : 

- https://195.156.61.126/global-protect/login.esp

Others are fixed

New PDF report generated by system 2021-11-22
Report comment dispatched to zythop by system 2021-11-22
Report comment dispatched to info@jcdecaux.be by system 2021-11-22
Report comment dispatched to vulnerabilitydisclosure@ccb.belgium.be by system 2021-11-22
Report edited by BloodyShell  2021-12-01
New PDF report generated by system 2021-12-01
Report marked as fixed by BloodyShell  2021-12-01
Report closed by BloodyShell  2021-12-01
New PDF report generated by system 2021-12-01
Report edited by BloodyShell  2021-12-05
New PDF report generated by system 2021-12-05
Information
Owner jcdecaux.be
Created 2021-11-14 09:42
Updated 2021-12-05 17:50
Fixed true

Contacts
i...@jcdecaux.be
v...@cert.be

Status
Status closed
Hosting contacted false
CERT contacted false

Download report