216.73.216.36

CVE-2025-0126

· Published 11/04/2025 02:15 · Modified 11/04/2025 15:39

Labels: CVE-2025-0126 2025-04-11CVE-2025-0126CWE-384[email protected]

Essential information

Published
11/04/2025 02:15
Modified
11/04/2025 15:39
Author
Creator
CVSS
8.3 HIGH (v3) 8.3 HIGH (v4.0)
CISA KEV
No
CWE
CVSS vector

CVSS metrics

Description

When configured using SAML, a session fixation vulnerability in the GlobalProtect™ login enables an attacker to impersonate a legitimate authorized user and perform actions as that GlobalProtect user. This requires the legitimate user to first click on a malicious link provided by the attacker. The SAML login for the PAN-OS® management interface is not affected. Additionally, this issue does not affect Cloud NGFW and all Prisma® Access instances are proactively patched.

NVD status

Status
Awaiting Analysis — CVE has been recently published to the CVE List and has been received by the NVD.
Source
[email protected]
NVD
View on NVD

Affected products (CPE)

ProductCPE
palo alto networks / globalprotect cpe:2.3:a:palo_alto_networks:globalprotect:*:*:*:*:*:*:*:*

References